The Ansible Collections Project maintains open-source automation and infrastructure-as-code modules, with observed vulnerabilities clustering in cryptographic and logging components such as the community.crypto collection. The durable signal centers on output-handling weaknesses including improper encoding and escaping in logs, reflecting the challenges of safely surfacing sensitive material in automation workflows; current exposure and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ansible Collections Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25646HIGH A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality | Oct 29, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ansible Collections Project.
Media articles that mention a CVE ID that affects a product developed by Ansible Collections Project — matched by CVE ID, not by vendor name.