CVEs (27)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Axios Redhat12Advanced Cluster Management For Kubernetes Advanced Cluster SecurityAnsible Automation Platform+9 moreSep 7, 2026 Jun 11, 2026 N/A· v4 7.7 HIGH· v3 N/A· v2 Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav...Show more |
2Js Cookie Redhat63scale Api Management Ansible Automation PlatformEnterprise Linux+3 moreSep 7, 2026 Jun 10, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced...Show more |
2Encode Redhat8Ai Inference Server Ansible Automation PlatformEnterprise Linux Ai+5 moreSep 4, 2026 May 26, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw...Show more |
1Redhat 1Ansible Automation Platform Aug 27, 2026 Apr 8, 2026 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certai...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideJun 17, 2026 Feb 27, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gatew...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideJun 17, 2026 Feb 27, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideJun 17, 2026 Feb 27, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the tes...Show more |
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information. |
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data. |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideJun 17, 2026 Oct 16, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL,...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreJun 17, 2026 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2Debian Redhat4Ansible Automation Platform Ansible DeveloperAnsible Inside+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreJun 17, 2026 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted...Show more |
1Redhat 2Ansible Automation Platform SatelliteJun 17, 2026 Nov 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the d...Show more |
33Akka AmazonApache+30 more166.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+163 moreAug 11, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideJun 17, 2026 Oct 4, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, r...Show more |
1Redhat 2Ansible Automation Platform Ansible CollectionJun 17, 2026 Oct 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the l...Show more |
1Redhat 4Ansible Automation Controller Ansible Automation PlatformAnsible Developer+1 moreJun 17, 2026 Oct 4, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. |
2Pulpproject Redhat4Ansible Automation Platform Pulp AnsibleSatellite+1 moreJun 17, 2026 Oct 25, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. |