Search CVE reports


Toggle filters

51 – 60 of 83 results


CVE-2019-14856

Medium priority
Not affected

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected
Show less packages

CVE-2019-14846

Low priority

Some fixes available 3 of 5

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-10217

Low priority
Ignored

A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected
Show less packages

CVE-2019-10206

Medium priority

Some fixes available 2 of 4

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-10156

Medium priority

Some fixes available 2 of 3

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Fixed
Show less packages

CVE-2018-16876

Medium priority

Some fixes available 1 of 2

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Fixed
Show less packages

CVE-2018-16837

Medium priority

Some fixes available 2 of 4

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10875

Medium priority

Some fixes available 2 of 3

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10874

Medium priority

Some fixes available 1 of 2

In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10855

Low priority

Some fixes available 1 of 2

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run...

1 affected package

ansible

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ansible Fixed
Show less packages