Ansible records
4 published records for vendor ansible.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2016-9587Proof of concept | Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems.ansible · ansible · CWE-20 | High8.1 | — | 17.1% | Apr 24, 2018 |
28Monitor | CVE-2015-1481Proof of concept | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.ansible · tower · CWE-264 | Medium6.5 | — | 6.1% | Feb 4, 2015 |
23Monitor | CVE-2015-1482Proof of concept | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websockeansible · tower · CWE-200 | Medium5.0 | — | 8.5% | Feb 4, 2015 |
19Monitor | CVE-2015-1368Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitraransible · tower · CWE-79 | Medium4.3 | — | 5.2% | Jan 27, 2015 |
- CVE-2016-958737Monitor
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems.
HighCVSS 8.1Proof of conceptEPSS 17%ansible · ansibleApr 24, 2018
- CVE-2015-148128Monitor
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
MediumCVSS 6.5Proof of conceptEPSS 6%ansible · towerFeb 4, 2015
- CVE-2015-148223Monitor
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocke
MediumCVSS 5.0Proof of conceptEPSS 9%ansible · towerFeb 4, 2015
- CVE-2015-136819Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrar
MediumCVSS 4.3Proof of conceptEPSS 5%ansible · towerJan 27, 2015