Ansible
Vendor:
First CVE: Sep 16, 2013 · Active for 12 years
45
Total CVEs
More Total CVEs than 98% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ansible over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2013
12 years ago
Most Recent CVE
Feb 6, 2024
903 days ago
CVE Severity & Scoring
Ansible45 CVEs
11%
47%
29%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local23 (51.1%)
Network19 (42.2%)
Unknown3 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (77.8%)
High7 (15.6%)
Unknown3 (6.7%)
User Interaction
None36 (80.0%)
Unknown3 (6.7%)
Required6 (13.3%)
Privileges Required
Low28 (62.2%)
High4 (8.9%)
None10 (22.2%)
Unknown3 (6.7%)
Top CVEs
Signals from CVEs in this product scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9587HIGH Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client sy | Apr 24, 2018 | 8.1 | 38 | NO | YES |
CVE-2014-4967CRITICAL Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a | Feb 18, 2020 | 9.8 | 33 | NO | NO |
CVE-2014-4657CRITICAL The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. | Feb 20, 2020 | 9.8 | 32 | NO | NO |
CVE-2014-4678CRITICAL The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: t | Feb 20, 2020 | 9.8 | 32 | NO | NO |
CVE-2017-7550CRITICAL A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to exp | Nov 21, 2017 | 9.8 | 32 | NO | NO |
CVE-2014-4966CRITICAL Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to exec | Feb 18, 2020 | 9.8 | 28 | NO | NO |
CVE-2017-7466HIGH Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by An | Jun 22, 2018 | 8.0 | 27 | NO | NO |
CVE-2022-3697HIGH A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advan | Oct 28, 2022 | 7.5 | 25 | NO | NO |
CVE-2016-8628CRITICAL Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller | Jul 31, 2018 | 9.1 | 25 | NO | NO |
CVE-2016-3096HIGH The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a syml | Jun 3, 2016 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (45 CVEs).
Media Mentions
Signals from CVEs in this product scope (45 CVEs).
Top CNAs Publishing CVEs For Ansible
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.16.0 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.10.1 | 2 | 6.3 | 0.3% | 0 | 0 |
| 2.0.1 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.0 | 1 | 7.8 | 0.5% | 0 | 0 |
| 1.2.2 | 1 | 3.3 | 0.3% | 0 | 0 |
| 1.2.1 | 1 | 3.3 | 0.3% | 0 | 0 |
| 1.2 | 1 | 3.3 | 0.3% | 0 | 0 |