Known vulnerabilities in ansible (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:ansible_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 17
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ansible (Red Hat package) ansible (Red Hat package) is affected by 17 known vulnerabilities: 1 high, 3 medium, 13 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU47274 - Improper Verification of Cryptographic Signature
CVE-2020-14365
CWE-347 Low
No
No
2.9.13-1.el7ae, 2.9.13-1.el8ae 23.09.2020 SB2020092344
SB2020100222
SB2020102019
and 12 more
#VU29566 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1746
CWE-200 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 07.07.2020 SB2020051276
SB2020041765
SB2021080804
and 9 more
#VU29564 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1739
CWE-200 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 07.07.2020 SB2020031237
SB2020031723
SB2021080804
and 12 more
#VU29029 - Information Exposure Through Log Files
CVE-2020-1753
CWE-532 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2021080804
and 11 more
#VU29028 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1740
CWE-200 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2020041764
and 12 more
#VU29026 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1737
CWE-22 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2020031722
and 12 more
#VU29024 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1735
CWE-22 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2021080804
and 11 more
#VU29023 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-1733
CWE-362 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2020041763
and 10 more
#VU29022 -
CVE-2020-10685
Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2021080804
and 10 more
#VU29017 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-10684
CWE-94 Low
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 15.06.2020 SB2020032420
SB2020061518
SB2021080804
and 11 more
#VU27558 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-10691
CWE-22 Medium
No
No
2.9.7-1.el7ae, 2.9.7-1.el8ae 06.05.2020 SB2020050603
SB2020041766
SB2020042252
and 6 more
#VU14158 - Permissions, Privileges, and Access Controls
CVE-2018-10875
CWE-264 Low
No
No
2.4.6.0-1.el7ae 01.08.2018 SB2018080113
SB2018073118
SB2019022302
and 11 more
#VU36808 - Command injection
CVE-2016-8628
CWE-77 High
No
No
2.2.0.0-1.el7 31.07.2018 SB2018073121
SB2024050721
SB2016110217
and 8 more
#VU14157 - Permissions, Privileges, and Access Controls
CVE-2018-10874
CWE-264 Low
No
No
2.4.6.0-1.el7ae 31.07.2018 SB2018080113
SB2018073118
SB2019011610
and 10 more
#VU13542 - Exposure of sensitive information to an unauthorized actor
CVE-2018-10855
CWE-200 Low
No
No
2.4.6.0-1.el7ae 02.07.2018 SB2018062711
SB2018062712
SB2018071210
and 10 more
#VU6640 - Improper Control of Generation of Code ('Code Injection')
CVE-2017-7481
CWE-94 Medium
No
No
2.2.3.0-1.el7 23.05.2017 SB2017052310
SB2017052601
SB2019022302
and 9 more
#VU6639 - Improper input validation
CVE-2017-7466
CWE-20 Medium
Available
No
2.2.1.0-1.el7, 2.2.3.0-1.el7 17.05.2017 SB2017052310
SB2017052601
SB2017070615
and 22 more