CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Ansible Automation Platform Nov 21, 2024 Aug 18, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remov...Show more |
1Redhat 2Ansible Automation Platform Ansible GalaxyNov 21, 2024 Apr 18, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in t...Show more |
1Redhat 3Ansible Automation Platform Ansible EngineAnsible TowerNov 21, 2024 Sep 22, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and th...Show more |
2Debian Redhat4Ansible Automation Platform Ansible EngineAnsible Tower+1 moreNov 21, 2024 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attack...Show more |