← Back

Ansible

ansible

4 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Tower
tower
Ansible
ansible

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Ansible
Redhat
3Ansible
AnsibleOpenstack
Nov 21, 2024
Apr 24, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ab...Show more
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.Show less
1Ansible
1Tower
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.
1Ansible
1Tower
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
1Ansible
1Tower
May 6, 2026
Jan 27, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) invento...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to api/v1/schedules/.Show less