ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-39059
An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

NVD description · AI analysis pending
8.82% PoC
  • ansible-semaphore ansible semaphore
CVE-2023-28609
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.

api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.

NVD description · AI analysis pending
9.8<1%
  • ansible-semaphore ansible semaphore
CVE-2020-25646
A flaw was found in Ansible Collection community.crypto.

A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality

NVD description · AI analysis pending
7.51%
  • ansible collections project community.crypto
CVE-2016-9587
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems.

Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

NVD description · AI analysis pending
8.117% PoC
  • redhat ansible
  • redhat openstack
CVE-2017-2809
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5.

An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.

NVD description · AI analysis pending
7.83% PoC
  • ansible-vault project ansible-vault