Community.general
Products
8- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
- 0 CVEs
- 0 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-87874 | Hig | 0.53 | 8.1 | 0.01 | Sep 9, 2026 | A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and… | ||
| CVE-2026-87872 | Med | 0.44 | 6.8 | 0.00 | Sep 9, 2026 | A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth… | ||
| CVE-2026-11820 | Med | 0.42 | 6.5 | 0.00 | Jun 23, 2026 | A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET requests. This causes credentials… | ||
| CVE-2026-16566 | mod | 0.40 | 6.1 | — | Jul 22, 2026 | community.general: community.general: jenkins_credential module returns generated API token in plaintext output | ||
| CVE-2026-80158 | Med | 0.36 | 5.5 | 0.00 | Aug 26, 2026 | A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the… |
- risk 0.53cvss 8.1epss 0.01
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and…
- risk 0.44cvss 6.8epss 0.00
A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth…
- risk 0.42cvss 6.5epss 0.00
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET requests. This causes credentials…
- risk 0.40cvss 6.1epss —
community.general: community.general: jenkins_credential module returns generated API token in plaintext output
- risk 0.36cvss 5.5epss 0.00
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the…