Known vulnerabilities in Ansible

Software: Ansible
Software CPE: cpe:2.3:a:red_hat:ansible:*:*:*:*:*:*:*:*
Total vulnerabilities: 59
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Ansible Ansible is affected by 59 known vulnerabilities: 8 high, 11 medium, 40 low Critical High Medium Low

Vulnerabilities (59)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU101827 - Security Features
CVE-2024-11079
CWE-254 High
No
No
2.15.13, 2.16.14, 2.17.7, 2.18.1 18.12.2024 SB2024121821
SB2024121823
SB2024121824
and 5 more
#VU100999 - Information Exposure Through Log Files
CVE-2024-8775
CWE-532 Low
No
No
2.14.18, 2.15.13, 2.16.13, 2.17.6 27.11.2024 SB2024112745
SB2024112746
SB2024120371
and 14 more
#VU100998 - Incorrect Authorization
CVE-2024-9902
CWE-863 Low
No
No
2.14.18, 2.15.13, 2.16.13, 2.17.6 27.11.2024 SB2024112745
SB2024112746
SB2024120371
and 15 more
#VU85621 - Missing release of memory after effective lifetime
CVE-2024-0690
CWE-401 Low
No
No
- 19.01.2024 SB2024011931
SB2024011933
SB2024011934
and 11 more
#VU84381 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-5764
CWE-94 Medium
No
No
2.14.12, 2.15.7, 2.16.1 13.12.2023 SB2023121315
SB2023121316
SB2023121317
and 16 more
#VU81467 - UNIX Symbolic Link (Symlink) Following
CVE-2023-5115
CWE-61 Low
No
No
2.16.0b2 04.10.2023 SB2023100466
SB2023100475
SB2023101275
and 9 more
#VU66553 - Permissions, Privileges, and Access Controls
CVE-2022-2568
CWE-264 Low
No
No
2.12.8 16.08.2022 SB2022081653
SB2022081654
SB2022081655
#VU57422 - Information Exposure Through an Error Message
CVE-2021-3620
CWE-209 Low
No
No
2.9.27, 2.9.27-1.el7ae, 2.9.27-1.el8ae, 2.9.27-1.el8ap 19.10.2021 SB2021101903
SB2021101904
SB2021101905
and 10 more
#VU55643 - Use of Insufficiently Random Values
CVE-2020-10729
CWE-330 Low
No
No
2.9.6 08.08.2021 SB2021080802
SB2021080804
SB2021092430
and 1 more
#VU54626 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3583
CWE-94 High
No
No
2.9.23, 2.9.23-1.el8ap 08.07.2021 SB2021070822
SB2021070823
SB2021071517
and 12 more
#VU52984 - Information Exposure Through Log Files
CVE-2021-3447
CWE-532 Low
No
No
2.9.20-1.el7ae, 2.9.20-1.el8ae, 2.9.21-1.el8ae 10.05.2021 SB2021040180
SB2021051001
SB2021072616
and 13 more
#VU50936 - Information Exposure Through Log Files
CVE-2021-20191
CWE-532 Low
No
No
2.8.19, 2.9.18, 2.10.6, 2.9.18-1.el7ae, 2.9.18-1.el8ae 25.02.2021 SB2021022511
SB2021022512
SB2021022513
and 11 more
#VU50818 - Information Exposure Through Log Files
CVE-2021-20228
CWE-532 Low
No
No
2.10.6, 2.9.18-1.el7ae, 2.9.18-1.el8ae 22.02.2021 SB2021022203
SB2021022205
SB2021022512
and 7 more
#VU50429 - Information Exposure Through Log Files
CVE-2021-20180
CWE-532 Low
No
No
2.10.6, 2.9.18-1.el7ae, 2.9.18-1.el8ae 09.02.2021 SB2021020903
SB2021020904
SB2021022512
and 11 more
#VU50428 - Information Exposure Through Log Files
CVE-2021-20178
CWE-532 Low
No
No
2.10.6, 2.9.18-1.el7ae, 2.9.18-1.el8ae 09.02.2021 SB2021020903
SB2021020904
SB2021022512
and 10 more
#VU47274 - Improper Verification of Cryptographic Signature
CVE-2020-14365
CWE-347 Low
No
No
2.8.15, 2.9.13, 2.8.15-1.el7ae, 2.8.15-1.el8ae, 2.9.13-1.el7ae, 2.9.13-1.el8ae 23.09.2020 SB2020092344
SB2020100222
SB2020102019
and 12 more
#VU29567 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-10744
CWE-362 Low
No
No
2.9.10 07.07.2020 SB2020051522
SB2024050721
#VU29566 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1746
CWE-200 Low
No
No
2.7.17, 2.8.11, 2.9.7, 2.7.17-1.el7ae, 2.8.11-1.el7ae, 2.8.11-1.el8ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae 07.07.2020 SB2020051276
SB2020041765
SB2021080804
and 9 more
#VU29029 - Information Exposure Through Log Files
CVE-2020-1753
CWE-532 Low
No
No
2.7.18-1.el7ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2021080804
and 11 more
#VU29024 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1735
CWE-22 Low
No
No
2.7.17-1.el7ae, 2.8.11-1.el7ae, 2.8.11-1.el8ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2021080804
and 11 more


Showing elements 1 - 20 out of 59