Known vulnerabilities in ansible-core (Red Hat package) - page 4
Vendor:
Red Hat Inc.
Software:
ansible-core (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:ansible-core_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
77
Public exploits:
5
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.16.19-1.el9ap
2.16.19-1.el10ap
2.14.18-3.el9
2.16.18-1.el8ap
2.16.18-1.el9ap
2.16.18-2.el10ap
2.16.17-1.el9ap
2.16.17-2.el10ap
2.16.16-1.el8ap
2.16.16-1.el9ap
2.16.15-1.el8ap
2.16.15-1.el9ap
2.16.15-2.el10ap
2.16.14-3.el10ap
2.15.13-2.el8ap
2.15.13-2.el9ap
2.14.18-1.el9
2.16.14-3.el9sat
2.16.14-2.el8ap
2.16.14-2.el9ap
2.16.14-1.el8ap
2.16.14-1.el9ap
2.15.13-1.el8ap
2.15.13-1.el9ap
2.16.13-1.el8ap
2.16.13-1.el9ap
2.15.12-1.el8ap
2.15.12-1.el9ap
2.15.11-1.el8ap
2.15.11-1.el9ap
2.16.3-2.el8
2.14.14-1.el9
2.15.10-1.el8ap
2.15.10-1.el9ap
2.15.9-1.el8ap
2.15.9-1.el9ap
2.15.8-1.el8ap
2.15.8-1.el9ap
2.15.5-1.el8ap
2.15.5-1.el9ap
2.14.11-1.el8ap
2.14.11-1.el9ap
2.15.4-1.el8ap
2.15.4-1.el9ap
2.14.9-1.el8ap
2.14.9-1.el9ap
2.15.3-1.el8ap
2.15.3-1.el9ap
2.11.2-2.el8ap
2.14.2-1.el8ap
2.14.2-1.el9ap
2.12.7-2.el8ap
2.11.6-1.el8ap
Vulnerabilities (77)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86190 - Resource exhaustion CVE-2024-24680 |
CWE-400 | Medium | 2.15.10-1.el8ap, 2.15.10-1.el9ap | 06.02.2024 |
SB2024020643 SB2024020644 SB2024021223 and 17 more |
||
| #VU85886 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-23334 |
CWE-22 | High | 2.15.10-1.el8ap, 2.15.10-1.el9ap | 30.01.2024 |
SB2024013007 SB2024013089 SB2024013101 and 18 more |
||
| #VU85884 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-23829 |
CWE-444 | Medium | 2.15.10-1.el8ap, 2.15.10-1.el9ap | 30.01.2024 |
SB2024013007 SB2024013089 SB2024013101 and 14 more |
||
| #VU85621 - Missing release of memory after effective lifetime CVE-2024-0690 |
CWE-401 | Low | 2.14.14-1.el9, 2.15.9-1.el8ap, 2.15.9-1.el9ap, 2.16.3-2.el8 | 19.01.2024 |
SB2024011931 SB2024011933 SB2024011934 and 11 more |
||
| #VU85368 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-22195 |
CWE-79 | Medium | 2.15.10-1.el8ap, 2.15.10-1.el9ap | 15.01.2024 |
SB2024011508 SB2024011512 SB2024011513 and 60 more |
||
| #VU84432 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-5189 |
CWE-22 | Medium | 2.15.8-1.el8ap, 2.15.8-1.el9ap | 14.12.2023 |
SB2023121427 SB2023121428 SB2024032846 and 1 more |
||
| #VU84381 - Improper Control of Generation of Code ('Code Injection') CVE-2023-5764 |
CWE-94 | Medium | 2.15.8-1.el8ap, 2.15.8-1.el9ap | 13.12.2023 |
SB2023121315 SB2023121316 SB2023121317 and 16 more |
||
| #VU81657 - Resource exhaustion CVE-2023-43665 |
CWE-400 | Medium | 2.15.5-1.el8ap, 2.15.5-1.el9ap | 05.10.2023 |
SB2023100544 SB2023100545 SB2023100546 and 16 more |
||
| #VU81467 - UNIX Symbolic Link (Symlink) Following CVE-2023-5115 |
CWE-61 | Low | 2.14.11-1.el8ap, 2.14.11-1.el9ap, 2.15.5-1.el8ap, 2.15.5-1.el9ap | 04.10.2023 |
SB2023100466 SB2023100475 SB2023101275 and 9 more |
||
| #VU81322 - Exposure of sensitive information to an unauthorized actor CVE-2023-43804 |
CWE-200 | Low | 2.15.9-1.el8ap, 2.15.9-1.el9ap | 02.10.2023 |
SB2023100251 SB2023100259 SB2023100260 and 112 more |
||
| #VU80395 - Resource exhaustion CVE-2023-41164 |
CWE-400 | Medium | 2.14.11-1.el8ap, 2.14.11-1.el9ap, 2.15.4-1.el8ap, 2.15.4-1.el9ap, 2.15.5-1.el8ap, 2.15.5-1.el9ap | 04.09.2023 |
SB2023090432 SB2023090550 SB2023091166 and 19 more |
||
| #VU79631 - Improper input validation CVE-2023-40267 |
CWE-20 | High | 2.14.9-1.el8ap, 2.14.9-1.el9ap, 2.15.3-1.el8ap, 2.15.3-1.el9ap | 16.08.2023 |
SB2023081631 SB20230821206 SB20230821207 and 9 more |
||
| #VU72036 - Error Handling CVE-2023-23931 |
CWE-388 | Low | 2.15.3-1.el8ap, 2.15.3-1.el9ap | 08.02.2023 |
SB2023020813 SB2023030952 SB2023031419 and 68 more |
||
| #VU71398 - Insufficient Verification of Data Authenticity CVE-2022-23491 |
CWE-345 | High | 2.14.2-1.el8ap, 2.14.2-1.el9ap | 20.01.2023 |
SB2023012034 SB2023012035 SB2023012036 and 51 more |
||
| #VU66553 - Permissions, Privileges, and Access Controls CVE-2022-2568 |
CWE-264 | Low | 2.12.7-2.el8ap | 16.08.2022 |
SB2022081653 SB2022081654 SB2022081655 |
||
| #VU57422 - Information Exposure Through an Error Message CVE-2021-3620 |
CWE-209 | Low | 2.11.6-1.el8ap | 19.10.2021 |
SB2021101903 SB2021101904 SB2021101905 and 10 more |
||
| #VU54626 - Improper Control of Generation of Code ('Code Injection') CVE-2021-3583 |
CWE-94 | High | 2.11.2-2.el8ap | 08.07.2021 |
SB2021070822 SB2021070823 SB2021071517 and 12 more |
Showing elements 61 - 80 out of 77