VYPR

Ansible

by Ansible

Source repositories

CVEs (6)

  • CVE-2018-16879CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.01

    Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service…

  • CVE-2016-9587HigApr 24, 2018
    risk 0.50cvss 8.1epss 0.17

    Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use…

  • CVE-2020-10782MedJun 18, 2020
    risk 0.42cvss 6.5epss 0.00

    An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable permissions. The highest threat from this…

  • CVE-2021-3583HigSep 22, 2021
    risk 0.39cvss 7.1epss 0.01

    A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special…

  • CVE-2021-20191MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this…

  • CVE-2025-53861LowJul 11, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.