CVE Tools

Ansible

5 CVEs tracked since 2015. Since Jan 2015, none of them reached CISA KEV.

Ansible CVEs per month

Jan 2015 to Nov 2019. Point at a month, or focus the strip and use the arrow keys.
Ansible CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0110
2015-0220
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-1120

Products

The products that kept showing up in Ansible's monthly top three, with their CVEs summed over those months.

  1. Tower32 months
  2. Ansible Engine21 month

Latest CVEs

The 11 most recently published vulnerabilities affecting Ansible.

  1. CVE-2025-7738Python3.11-django-ansible-base: sensitive authenticator secrets returned in clear text via api in aap4.4
  2. CVE-2024-11079Ansible-core: unsafe tagging bypass via hostvars object in ansible-core5.5
  3. CVE-2024-8775Ansible-core: exposure of sensitive information in ansible vault files due to improper logging5.5
  4. CVE-2019-14856ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None6.5
  5. CVE-2019-10206ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could cont...6.5
  6. CVE-2019-14846In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plug...7.8
  7. CVE-2018-10874In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.7.8
  8. CVE-2016-9587Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being manage...8.1
  9. CVE-2015-1482Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.5.0
  10. CVE-2015-1481Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.6.5
  11. CVE-2015-1368Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to cr...4.3

The record

Peak rank
#42 in Feb 2015
Busiest month shown
Feb 2015, 2 CVEs
Months with a KEV entry
0 since Jan 2015
Monthly snapshots
3 since 2015
Ansible's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store