Known vulnerabilities in Ansible Automation Platform - page 14

Software CPE: cpe:2.3:a:red_hat:ansible_automation_platform:*:*:*:*:*:*:*:*
Total vulnerabilities: 321
Public exploits: 26
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Ansible Automation Platform Ansible Automation Platform is affected by 321 known vulnerabilities: 1 critical, 58 high, 172 medium, 90 low Critical High Medium Low

Vulnerabilities (321)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78883 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-3971
CWE-79 Low
No
No
- 02.08.2023 SB2023080246
SB2023081026
#VU71398 - Insufficient Verification of Data Authenticity
CVE-2022-23491
CWE-345 High
No
No
- 20.01.2023 SB2023012034
SB2023012035
SB2023012036
and 51 more
#VU66553 - Permissions, Privileges, and Access Controls
CVE-2022-2568
CWE-264 Low
No
No
2.1.3 16.08.2022 SB2022081653
SB2022081654
SB2022081655
#VU62051 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28347
CWE-89 High
No
No
2.1.2 11.04.2022 SB2022041110
SB2022041125
SB2022041267
and 8 more
#VU62050 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28346
CWE-89 High
Available
No
2.1.2 11.04.2022 SB2022041110
SB2022041125
SB2022041126
and 14 more
#VU60371 - Permissions, Privileges, and Access Controls
CVE-2021-4112
CWE-264 Medium
No
No
2.1 08.02.2022 SB2022020816
SB2022020817
SB2022020904
and 2 more
#VU57422 - Information Exposure Through an Error Message
CVE-2021-3620
CWE-209 Low
No
No
2.0.1 19.10.2021 SB2021101903
SB2021101904
SB2021101905
and 10 more
#VU55500 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23980
CWE-79 Medium
No
No
- 02.08.2021 SB2021080212
SB2021080213
SB2021041804
and 3 more
#VU55499 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-7789
CWE-78 High
No
No
- 02.08.2021 SB2020121118
SB2021080213
SB2023071326
and 2 more
#VU55498 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-15366
CWE-94 Medium
No
No
- 02.08.2021 SB2020071552
SB2021080213
SB2020120120
and 14 more
#VU54626 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3583
CWE-94 High
No
No
2.0.0 08.07.2021 SB2021070822
SB2021070823
SB2021071517
and 12 more
#VU54077 - Resource exhaustion
CVE-2021-33503
CWE-400 Medium
No
No
1.2.5 13.06.2021 SB2021061304
SB2021061305
SB2021071501
and 36 more
#VU53543 - Off-by-one Error
CVE-2021-23017
CWE-193 High
Available
No
1.2.4 25.05.2021 SB2021052543
SB2021052713
SB2021052901
and 48 more
#VU51776 - Resource Management Errors
CVE-2021-27291
CWE-399 Medium
No
No
- 30.03.2021 SB2021031407
SB2021033004
SB2021041202
and 17 more
#VU51449 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-20270
CWE-835 Low
No
No
- 14.03.2021 SB2021031407
SB2021031410
SB2021041202
and 14 more
#VU50780 - Memory corruption
CVE-2020-8625
CWE-119 High
No
No
1.2.4 17.02.2021 SB2021021718
SB2021021908
SB2021022703
and 28 more
#VU50172 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-3281
CWE-22 High
Available
No
- 01.02.2021 SB2021020117
SB2021020612
SB2021080213
and 7 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Available
No
1.2.4 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more
#VU32881 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-20907
CWE-835 Medium
No
No
1.2.4 29.07.2020 SB2020071324
SB2020080201
SB2020082408
and 53 more
#VU24487 - Missing release of memory after effective lifetime
CVE-2019-20388
CWE-401 Medium
No
No
1.0, 1.1, 1.2.4 22.01.2020 SB2020012220
SB2020052301
SB2020062607
and 28 more


Showing elements 261 - 280 out of 321