CVEs (64)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive in...Show more |
3Debian RedhatSuse4Ansible Engine Ansible TowerDebian Linux+1 moreNov 21, 2024 Oct 23, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing...Show more |
4Canonical DebianParamiko+1 more11Ansible Tower Debian LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Oct 8, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. |
4Canonical DebianGit Scm+1 more11Ansible Tower Debian LinuxEnterprise Linux+8 moreNov 21, 2024 Oct 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproj...Show more |
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to g...Show more |
1Redhat 2Ansible Tower Cloudforms Management EngineNov 21, 2024 Aug 22, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback). |
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malici...Show more |
4Canonical DebianRedhat+1 more7Ansible Tower Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. |
5Cabextract Cabextract ProjectCanonical+2 more8Ansible Tower CabextractDebian Linux+5 moreNov 21, 2024 Jul 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. |
5Cabextract Cabextract ProjectCanonical+2 more8Ansible Tower CabextractDebian Linux+5 moreNov 21, 2024 Jul 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite. |
5Cabextract Cabextract ProjectCanonical+2 more8Ansible Tower CabextractDebian Linux+5 moreNov 21, 2024 Jul 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. |
5Cabextract Cabextract ProjectCanonical+2 more8Ansible Tower CabextractDebian Linux+5 moreNov 21, 2024 Jul 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference...Show more |
1Redhat 2Ansible Tower CloudformsNov 21, 2024 Jul 27, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access...Show more |
4Canonical DebianFreedesktop+1 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jul 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of...Show more |
5Canonical DebianGnome+2 more9Ansible Tower Debian LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 Jul 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. |
5Canonical DebianFedoraproject+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service. |
5Canonical DebianFedoraproject+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. |
5Canonical DebianGnupg+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 13, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign functi...Show more |
4Canonical DebianFreedesktop+1 more7Ansible Tower Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 May 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops. |
4Canonical DebianFreedesktop+1 more7Ansible Tower Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 May 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages suc...Show more |