VYPR

Ansible Automation Platform Early Access

by Red Hat

CVEs (2)

  • CVE-2021-4112HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.

  • CVE-2021-3620MedMar 3, 2022
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.