Show filters
158 Total Results
Displaying 111-120 of 158
Sort by:
Attacker Value
Unknown

CVE-2019-3835

Disclosure Date: March 25, 2019 (last updated November 08, 2023)
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Attacker Value
Unknown

CVE-2018-16876

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
Attacker Value
Unknown

CVE-2018-16879

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
Attacker Value
Unknown

CVE-2018-16859

Disclosure Date: November 29, 2018 (last updated November 27, 2024)
Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the plaintext password. Ansible Engine 2.8 and older are believed to be vulnerable.
0
Attacker Value
Unknown

CVE-2018-16837

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.
0
Attacker Value
Unknown

CVE-2018-1000805

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Attacker Value
Unknown

CVE-2018-17456

Disclosure Date: October 06, 2018 (last updated November 27, 2024)
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
0
Attacker Value
Unknown

CVE-2016-7070

Disclosure Date: September 11, 2018 (last updated November 27, 2024)
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.
0
Attacker Value
Unknown

CVE-2017-7528

Disclosure Date: August 22, 2018 (last updated November 27, 2024)
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).
0
Attacker Value
Unknown

CVE-2018-10884

Disclosure Date: August 22, 2018 (last updated November 27, 2024)
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.
0