VYPR

Ansible Tower

by Red Hat

Source repositories

CVEs (65)

  • CVE-2020-1736LowMar 16, 2020
    risk 0.14cvss 2.2epss 0.00

    A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less…

  • CVE-2018-17456CriOct 6, 2018
    risk 0.11cvss 9.8epss 0.97

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a…

  • CVE-2020-1738LowMar 16, 2020
    risk 0.00cvss 3.9epss 0.00

    A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x,…

  • CVE-2019-3869HigMar 28, 2019
    risk 0.00cvss 7.2epss 0.01

    When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

  • CVE-2018-13988MedJul 25, 2018
    risk 0.00cvss 6.5epss 0.03

    Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a…

Page 4 of 4