CVE Tools

Ansible Tower

75 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Ansible Tower, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Ansible Tower CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ansible Tower CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 75 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical57%
  • High2736%
  • Medium3648%
  • Low79%

Latest CVEs

The 15 most recently published vulnerabilities affecting Ansible Tower.

  1. CVE-2024-11236Integer overflow in the firebird and dblib quoters causing OOB writes9.8
  2. CVE-2021-4112A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX us...8.8
  3. CVE-2021-43818HTML Cleaner allows crafted and SVG embedded scripts to pass through8.2
  4. CVE-2021-3583A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-l...7.1
  5. CVE-2021-23017A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process c...7.7
  6. CVE-2020-14329A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in t...3.3
  7. CVE-2020-14328A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal s...3.3
  8. CVE-2020-14327A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the...5.5
  9. CVE-2020-10709A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain...7.1
  10. CVE-2020-10698A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible data can be disclos...3.3
  11. CVE-2020-10697A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a den...4.4
  12. CVE-2021-20191A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage...5.5
  13. CVE-2021-20178A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This fl...5.5
  14. CVE-2021-20228A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. Thi...7.5
  15. CVE-2021-3447A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the control...5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store