CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certai...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideMar 25, 2026 Feb 27, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gatew...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideMar 25, 2026 Feb 27, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideMar 26, 2026 Feb 27, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the tes...Show more |
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information. |
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data. |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideMar 26, 2025 Oct 16, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL,...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreNov 4, 2025 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreMar 24, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2Debian Redhat4Ansible Automation Platform Ansible DeveloperAnsible Inside+1 moreDec 6, 2024 Dec 18, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreNov 21, 2024 Dec 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted...Show more |
1Redhat 2Ansible Automation Platform SatelliteDec 6, 2024 Nov 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the d...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreMay 12, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideNov 21, 2024 Oct 4, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, r...Show more |
1Redhat 2Ansible Automation Platform Ansible CollectionNov 21, 2024 Oct 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the l...Show more |
1Redhat 4Ansible Automation Controller Ansible Automation PlatformAnsible Developer+1 moreNov 21, 2024 Oct 4, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. |
2Pulpproject Redhat4Ansible Automation Platform Pulp AnsibleSatellite+1 moreMay 7, 2025 Oct 25, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. |
1Redhat 1Ansible Automation Platform Nov 21, 2024 Sep 13, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection |
2Fedoraproject Redhat3Ansible Automation Platform FedoraOpenshift Container PlatformNov 21, 2024 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allo...Show more |
1Redhat 4Ansible Automation Platform Ansible Automation Platform Early AccessAnsible Automation Platform Text Only Advisories+1 moreNov 21, 2024 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the iso...Show more |