Ansible's vulnerability footprint centers on its automation and configuration-management platform, where the durable signal reflects application-layer security challenges including sensitive information exposure, improper input validation, and cross-site scripting in its web interfaces and tower management console. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ansible over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9587HIGH Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client sy | Apr 24, 2018 | 8.1 | 38 | NO | YES |
CVE-2015-1481MEDIUM Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account. | Feb 4, 2015 | 6.5 | 28 | NO | YES |
CVE-2015-1482MEDIUM Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/. | Feb 4, 2015 | 5.0 | 25 | NO | YES |
CVE-2015-1368MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_b | Jan 27, 2015 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ansible.
Media articles that mention a CVE ID that affects a product developed by Ansible — matched by CVE ID, not by vendor name.