Known vulnerabilities in Ansible - page 3

Software: Ansible
Software CPE: cpe:2.3:a:red_hat:ansible:*:*:*:*:*:*:*:*
Total vulnerabilities: 59
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Ansible Ansible is affected by 59 known vulnerabilities: 8 high, 11 medium, 40 low Critical High Medium Low

Vulnerabilities (59)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU30582 - Exposure of sensitive information to an unauthorized actor
CVE-2019-10217
CWE-200 Medium
No
No
2.8.4, 2.8.4-1.el7ae, 2.8.4-1.el8ae 25.11.2019 SB2019112223
SB2020072802
SB2020041628
and 6 more
#VU30585 - Improper input validation
CVE-2019-10206
CWE-20 Medium
No
No
2.8.4, 2.6.19-1.el7ae, 2.6.20-1.el7ae, 2.7.13-1.el7ae, 2.8.4-1.el7ae, 2.8.4-1.el8ae 22.11.2019 SB2019112223
SB2020072802
SB2020041628
and 14 more
#VU22872 - Exposure of sensitive information to an unauthorized actor
CVE-2019-14864
CWE-200 Low
No
No
2.7.15, 2.8.7, 2.9.1 20.11.2019 SB2019112014
SB2020041628
SB2020041306
and 2 more
#VU21766 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-3828
CWE-22 High
No
No
2.5.15, 2.6.14, 2.7.8, 2.5.15-1.el7ae, 2.6.14-1.el7ae, 2.6.19-1.el7ae, 2.7.8-1.el7ae 14.10.2019 SB2019032710
SB2019081432
SB2019062713
and 13 more
#VU30975 - Exposure of sensitive information to an unauthorized actor
CVE-2019-10156
CWE-200 Medium
No
No
2.8.2, 2.6.18-1.el7ae, 2.6.19-1.el7ae, 2.7.12-1.el7ae, 2.8.2-1.el7ae, 2.8.2-1.el8ae 31.07.2019 SB2019073113
SB2019080219
SB2021080804
and 10 more
#VU16629 - Exposure of sensitive information to an unauthorized actor
CVE-2018-16876
CWE-200 Low
No
No
2.5.14, 2.6.11, 2.7.5 19.12.2018 SB2018122008
SB2019022302
SB2019031413
and 9 more
#VU16312 - Exposure of sensitive information to an unauthorized actor
CVE-2018-16859
CWE-200 Low
No
No
2.5.13, 2.6.10, 2.7.4, 2.5.13-1.el7ae, 2.6.10-1.el7ae, 2.7.4-1.el7ae 05.12.2018 SB2018120610
SB2019022302
SB2019081432
and 8 more
#VU15721 - Exposure of sensitive information to an unauthorized actor
CVE-2018-16837
CWE-200 Low
No
No
2.5.11, 2.6.7, 2.7.1 05.11.2018 SB2018110510
SB2019081432
SB2019062713
and 4 more
#VU14158 - Permissions, Privileges, and Access Controls
CVE-2018-10875
CWE-264 Low
No
No
2.5.6-1.el7ae, 2.6.1-1.el7ae 01.08.2018 SB2018080113
SB2018073118
SB2019022302
and 11 more
#VU36806 - Key Management Errors
CVE-2016-8614
CWE-320 Medium
No
No
2.2.0 31.07.2018 SB2018073121
SB2024050721
SB2016110217
and 7 more
#VU36808 - Command injection
CVE-2016-8628
CWE-77 High
No
No
2.2.0 31.07.2018 SB2018073121
SB2024050721
SB2016110217
and 8 more
#VU14157 - Permissions, Privileges, and Access Controls
CVE-2018-10874
CWE-264 Low
No
No
2.5.6-1.el7ae, 2.6.1-1.el7ae 31.07.2018 SB2018080113
SB2018073118
SB2019011610
and 10 more
#VU13542 - Exposure of sensitive information to an unauthorized actor
CVE-2018-10855
CWE-200 Low
No
No
2.4.5, 2.5.5, 2.5.5-1.el7ae 02.07.2018 SB2018062711
SB2018062712
SB2018071210
and 10 more
#VU12421 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2013-2233
CWE-300 Low
No
No
- 08.05.2018 SB2012081301
SB2013070508
#VU12555 - Information Exposure Through Log Files
CVE-2017-7550
CWE-532 Low
No
No
- 05.03.2018 SB2018030511
SB2017101940
SB2024050718
and 4 more
#VU7411 - Improper input validation
CVE-2016-8647
CWE-20 Low
No
No
- 11.07.2017 SB2017070615
SB2024050718
SB2024050721
and 4 more
#VU6639 - Improper input validation
CVE-2017-7466
CWE-20 Medium
Available
No
- 17.05.2017 SB2017052310
SB2017052601
SB2017070615
and 22 more
#VU40252 - Improper Link Resolution Before File Access ('Link Following')
CVE-2016-3096
CWE-59 Low
No
No
- 03.06.2016 SB2016060301
SB2016072022
SB2016041502
and 10 more
#VU42561 - Permissions, Privileges, and Access Controls
CVE-2013-4260
CWE-264 Medium
No
No
- 16.09.2013 SB2013091608


Showing elements 41 - 60 out of 59