<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ansible (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ansible.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ansible-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ansible (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-14377 – A security issue was discovered within the legacy Ansible playbook component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14377</guid>
    <pubDate>Tue, 20 Jan 2026 14:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14377</strong></p>
  <p>A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14025 – A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14025</guid>
    <pubDate>Thu, 08 Jan 2026 14:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14025</strong></p>
  <p>A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were exploited, an attacker‘s capabilities would only be limited by role based access contr…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-279</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49521 – A flaw was found in the EDA component of the Ansible Automation Platform, where ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49521</guid>
    <pubDate>Mon, 30 Jun 2025 21:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49521</strong></p>
  <p>A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49520 – A flaw was found in Ansible Automation Platform’s EDA component where user-suppl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49520</guid>
    <pubDate>Mon, 30 Jun 2025 21:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49520</strong></p>
  <p>A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands on the EDA worker. In Kubernetes/OpenShift environments, this can lead to service account token theft and cluster access.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1801 – A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1801</guid>
    <pubDate>Mon, 03 Mar 2025 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1801</strong></p>
  <p>A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the server to be jeopardized. A user session or confidential data might be vulnerable.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53979 – ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53979</guid>
    <pubDate>Fri, 29 Nov 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53979</strong></p>
  <p>ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and into the output returned by some of its Ansible module in the following cases: 1. The 'boot_ftp_password' and 'ssc_master_pw' properties are passed as input to the zhmc_partition Ansible module. 2. The 'ssc_master_pw' and 'zaware_master…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40629 – JumpServer is an open-source Privileged Access Management (PAM) tool that provid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40629</guid>
    <pubDate>Thu, 18 Jul 2024 17:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40629</strong></p>
  <p>JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the Ansible playbook to write arbitrary files, leading to remote code execution (RCE) in the Celery container. The Celery container runs as root and has datab…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40628 – JumpServer is an open-source Privileged Access Management (PAM) tool that provid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40628</guid>
    <pubDate>Thu, 18 Jul 2024 17:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40628</strong></p>
  <p>JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the ansible playbook to read arbitrary files in the celery container, leading to sensitive information disclosure. The Celery container runs as root and has d…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36110 – ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36110</guid>
    <pubDate>Tue, 28 May 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36110</strong></p>
  <p>ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser. These issues have been addressed in version 0.0.21 (0.0.21.post2 on pypi). Users are advised to upgrade. There are no known workarounds for these issues.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1657 – A flaw was found in the ansible automation platform. An insecure WebSocket conne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1657</guid>
    <pubDate>Thu, 25 Apr 2024 17:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1657</strong></p>
  <p>A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity of the system.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29202 – JumpServer is an open source bastion host and an operation and maintenance secur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29202</guid>
    <pubDate>Fri, 29 Mar 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29202</strong></p>
  <p>JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the dat…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29201 – JumpServer is an open source bastion host and an operation and maintenance secur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29201</guid>
    <pubDate>Fri, 29 Mar 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29201</strong></p>
  <p>JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the database. This…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5764 – A template injection flaw was found in Ansible where a user's controller interna...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5764</guid>
    <pubDate>Tue, 12 Dec 2023 22:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5764</strong></p>
  <p>A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4237 – A flaw was found in the Ansible Automation Platform. When creating a new keypair...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4237</guid>
    <pubDate>Wed, 04 Oct 2023 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4237</strong></p>
  <p>A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39059 – An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39059</guid>
    <pubDate>Mon, 28 Aug 2023 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39059</strong></p>
  <p>An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-28609 – api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28609</guid>
    <pubDate>Sat, 18 Mar 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-28609</strong></p>
  <p>api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3697 – A flaw was found in Ansible in the amazon.aws collection when using the tower_ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3697</guid>
    <pubDate>Fri, 28 Oct 2022 16:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3697</strong></p>
  <p>A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-233</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4112 – A flaw was found in ansible-tower where the default installation is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4112</guid>
    <pubDate>Thu, 25 Aug 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4112</strong></p>
  <p>A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4041 – A flaw was found in ansible-runner. An improper escaping of the shell command, w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4041</guid>
    <pubDate>Wed, 24 Aug 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4041</strong></p>
  <p>A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3589 – An authorization flaw was found in Foreman Ansible. An authenticated attacker wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3589</guid>
    <pubDate>Wed, 23 Mar 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3589</strong></p>
  <p>An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33924 – Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33924</guid>
    <pubDate>Wed, 29 Sep 2021 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33924</strong></p>
  <p>Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3583 – A flaw was found in Ansible, where a user's controller is vulnerable to template...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3583</guid>
    <pubDate>Wed, 22 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3583</strong></p>
  <p>A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses sensitive information. The hig…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21382 – Restund is an open source NAT traversal server. The restund TURN server can be i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21382</guid>
    <pubDate>Fri, 11 Jun 2021 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21382</strong></p>
  <p>Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship (https://github.com/wireapp/ansible-restund/blob/master/templates/restund.conf.j2#L40-L43) the `status` interface of restund is en…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1716 – A flaw was found in the ceph-ansible playbook where it contained hardcoded passw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1716</guid>
    <pubDate>Fri, 28 May 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1716</strong></p>
  <p>A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configuratio…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10709 – A security flaw was found in Ansible Tower when requesting an OAuth2 token with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10709</guid>
    <pubDate>Thu, 27 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10709</strong></p>
  <p>A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The original token granted to the user still has access to Ansible Tower, which allows any user that can gain access to the token to be fully authenticated to Ansi…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31918 – A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31918</guid>
    <pubDate>Thu, 06 May 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31918</strong></p>
  <p>A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20228 – A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not maske...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20228</guid>
    <pubDate>Thu, 29 Apr 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20228</strong></p>
  <p>A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19350 – An insecure modification vulnerability in the /etc/passwd file was found in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19350</guid>
    <pubDate>Wed, 24 Mar 2021 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19350</strong></p>
  <p>An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25646 – A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25646</guid>
    <pubDate>Thu, 29 Oct 2020 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25646</strong></p>
  <p>A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14365 – A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14365</guid>
    <pubDate>Wed, 23 Sep 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14365</strong></p>
  <p>A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package ins…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14904 – A flaw was found in the solaris_zone module from the Ansible Community modules. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14904</guid>
    <pubDate>Wed, 26 Aug 2020 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14904</strong></p>
  <p>A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the remote host. Ansible Engine 2.7.15, 2.8.7, and…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14296 – Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14296</guid>
    <pubDate>Tue, 11 Aug 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14296</strong></p>
  <p>Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-17954 – An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE Open...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17954</guid>
    <pubDate>Fri, 03 Apr 2020 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-17954</strong></p>
  <p>An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause become root on any other node. This issue affects: SUSE OpenStack Cloud 7 crowbar-core versions prior to 4.0+git.1578392992.fabfd186c-9.63.1, crowbar-. SUSE OpenS…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10684 – A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10684</guid>
    <pubDate>Tue, 24 Mar 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10684</strong></p>
  <p>A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which w…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19355 – An insecure modification vulnerability in the /etc/passwd file was found in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19355</guid>
    <pubDate>Wed, 18 Mar 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19355</strong></p>
  <p>An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift 4.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1737 – A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1737</guid>
    <pubDate>Mon, 09 Mar 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1737</strong></p>
  <p>A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1734 – A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1734</guid>
    <pubDate>Tue, 03 Mar 2020 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1734</strong></p>
  <p>A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run arbitrary commands by overwriting the ansible facts.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-4657 – The safe_eval function in Ansible before 1.5.4 does not properly restrict the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-4657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-4657</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-4657</strong></p>
  <p>The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-4657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-4678 – The safe_eval function in Ansible before 1.6.4 does not properly restrict the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-4678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-4678</guid>
    <pubDate>Thu, 20 Feb 2020 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-4678</strong></p>
  <p>The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-4678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-4967 – Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-4967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-4967</guid>
    <pubDate>Tue, 18 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-4967</strong></p>
  <p>Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing " temp=" clause, or (3) a trailing " validate=" clause accompanied by a shell command.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-4967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-4966 – Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" subs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-4966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-4966</guid>
    <pubDate>Tue, 18 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-4966</strong></p>
  <p>Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-4966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2686 – Ansible prior to 1.5.4 mishandles the evaluation of some strings.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2686</guid>
    <pubDate>Thu, 09 Jan 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2686</strong></p>
  <p>Ansible prior to 1.5.4 mishandles the evaluation of some strings.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19340 – A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19340</guid>
    <pubDate>Thu, 19 Dec 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19340</strong></p>
  <p>A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14890 – A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14890</guid>
    <pubDate>Tue, 26 Nov 2019 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14890</strong></p>
  <p>A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14846 – In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14846</guid>
    <pubDate>Tue, 08 Oct 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14846</strong></p>
  <p>In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are executed in a separate process.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15149 – core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15149</guid>
    <pubDate>Sun, 18 Aug 2019 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15149</strong></p>
  <p>core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10139 – During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible varia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10139</guid>
    <pubDate>Fri, 17 May 2019 16:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10139</strong></p>
  <p>During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10311 – A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10311</guid>
    <pubDate>Tue, 30 Apr 2019 13:29:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10311</strong></p>
  <p>A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10310 – A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10310</guid>
    <pubDate>Tue, 30 Apr 2019 13:29:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10310</strong></p>
  <p>A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-16879 – Ansible Tower before version 3.3.3 does not set a secure channel as it is using ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16879</guid>
    <pubDate>Thu, 03 Jan 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-16879</strong></p>
  <p>Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16837 – Ansible "User" module leaks any data which is passed on as a parameter to ssh-ke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16837</guid>
    <pubDate>Tue, 23 Oct 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16837</strong></p>
  <p>Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-214</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-7070 – A privilege escalation flaw was found in the Ansible Tower. When Tower before 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7070</guid>
    <pubDate>Tue, 11 Sep 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-7070</strong></p>
  <p>A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10884 – Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10884</guid>
    <pubDate>Wed, 22 Aug 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10884</strong></p>
  <p>Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8628 – Ansible before version 2.2.0 fails to properly sanitize fact variables sent from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8628</guid>
    <pubDate>Tue, 31 Jul 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8628</strong></p>
  <p>Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12148 – A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12148</guid>
    <pubDate>Fri, 27 Jul 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12148</strong></p>
  <p>A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by Tower, modifies the checked out SCM repository to add git hooks. These git hooks…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7481 – Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7481</guid>
    <pubDate>Thu, 19 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7481</strong></p>
  <p>Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not evaluated.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10875 – A flaw was found in ansible. ansible.cfg is read from the current working direct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10875</guid>
    <pubDate>Fri, 13 Jul 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10875</strong></p>
  <p>A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10874 – In ansible it was found that inventory variables are loaded from current working...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10874</guid>
    <pubDate>Mon, 02 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10874</strong></p>
  <p>In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7466 – Ansible before version 2.3 has an input validation vulnerability in the handling...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7466</guid>
    <pubDate>Fri, 22 Jun 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7466</strong></p>
  <p>Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1085 – openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1085</guid>
    <pubDate>Fri, 15 Jun 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1085</strong></p>
  <p>openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER_CLIENT_CERT_AUTH in etcd.conf result in etcd being configured to allow remote users to connect without any authentication if they can access the etcd server bound to the network…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-592</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2233 – Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2233</guid>
    <pubDate>Fri, 04 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2233</strong></p>
  <p>Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1104 – Ansible Tower through version 3.2.3 has a vulnerability that allows users only w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1104</guid>
    <pubDate>Wed, 02 May 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1104</strong></p>
  <p>Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1101 – Ansible Tower before version 3.2.4 has a flaw in the management of system and or...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1101</guid>
    <pubDate>Wed, 02 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1101</strong></p>
  <p>Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9587 – Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9587</guid>
    <pubDate>Tue, 24 Apr 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9587</strong></p>
  <p>Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-2186 – The Ansible edxapp role in the Configuration Repo in edX allows remote websites ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2186</guid>
    <pubDate>Sat, 03 Feb 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-2186</strong></p>
  <p>The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7550 – A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7550</guid>
    <pubDate>Tue, 21 Nov 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7550</strong></p>
  <p>A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2809 – An exploitable vulnerability exists in the yaml loading functionality of ansible...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2809</guid>
    <pubDate>Thu, 14 Sep 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2809</strong></p>
  <p>An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3498 – The user module in ansible before 1.6.6 allows remote authenticated users to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3498</guid>
    <pubDate>Thu, 08 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3498</strong></p>
  <p>The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6240 – The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6240</guid>
    <pubDate>Wed, 07 Jun 2017 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6240</strong></p>
  <p>The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3096 – The create_script function in the lxc_container module in Ansible before 1.9.6-1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3096</guid>
    <pubDate>Fri, 03 Jun 2016 14:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3096</strong></p>
  <p>The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3096">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
