VYPR

rpm package

opensuse/ansible&distro=openSUSE Leap 15.0

pkg:rpm/opensuse/ansible&distro=openSUSE%20Leap%2015.0

Vulnerabilities (5)

  • CVE-2019-3828Mar 27, 2019
    affected < 2.7.8-bp150.3.6.1fixed 2.7.8-bp150.3.6.1

    Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

  • CVE-2018-16876Jan 3, 2019
    affected < 2.7.8-bp150.3.6.1fixed 2.7.8-bp150.3.6.1

    ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

  • CVE-2018-16859Nov 29, 2018
    affected < 2.7.8-bp150.3.6.1fixed 2.7.8-bp150.3.6.1

    Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can allow for 'become' passwords to appear in EventLogs in plaintext. A local user with administrator privileges on the machine can view these logs and discover the

  • CVE-2018-16837Oct 23, 2018
    affected < 2.7.8-bp150.3.6.1fixed 2.7.8-bp150.3.6.1

    Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which h

  • CVE-2018-10875Jul 13, 2018
    affected < 2.7.8-bp150.3.6.1fixed 2.7.8-bp150.3.6.1

    A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.