Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-36110
Disclosure Date: May 28, 2024 (last updated May 29, 2024)
ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser. These issues have been addressed in version 0.0.21 (0.0.21.post2 on pypi). Users are advised to upgrade. There are no known workarounds for these issues.
0
Attacker Value
Unknown
CVE-2023-39059
Disclosure Date: August 28, 2023 (last updated October 08, 2023)
An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.
0
Attacker Value
Unknown
CVE-2023-28609
Disclosure Date: March 18, 2023 (last updated October 08, 2023)
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
0
Attacker Value
Unknown
CVE-2014-125036
Disclosure Date: January 02, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as problematic, has been found in drybjed ansible-ntp. Affected by this issue is some unknown functionality of the file meta/main.yml. The manipulation leads to insufficient control of network message volume. The attack can only be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The patch is identified as ed4ca2cf012677973c220cdba36b5c60bfa0260b. It is recommended to apply a patch to fix this issue. VDB-217190 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2020-25646
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality
0
Attacker Value
Unknown
CVE-2016-9587
Disclosure Date: April 24, 2018 (last updated November 08, 2023)
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
0
Attacker Value
Unknown
CVE-2017-2809
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2015-1482
Disclosure Date: February 04, 2015 (last updated October 05, 2023)
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.
0
Attacker Value
Unknown
CVE-2015-1481
Disclosure Date: February 04, 2015 (last updated October 05, 2023)
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
0
Attacker Value
Unknown
CVE-2015-1368
Disclosure Date: January 27, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to api/v1/schedules/.
0