End of life: 6/18/2026, Latest version: 13.8.0
End of life: 12/9/2025, Latest version: 12.3.0
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.
A flaw was found in Ansible. Three API endpoints were accessed and returned verbose, unauthenticated responses, which may contain important information for an malicious user to perform other attacks.
End of life: 12/9/2025, Latest version: 11.13.0
End of life: 12/9/2025, Latest version: 11.13.0
This CVE affects Ansible and is similar to CVE-2024-0690. The vulnerability arises due to improper handling of sensitive variables loaded from Ansible Vault files, potentially leading to the exposure of secret data during execution.
End of life: 11/30/2024, Latest version: 2.15.13
End of life: 11/30/2024, Latest version: 2.15.13
End of life: 5/20/2024, Latest version: 2.14.18
End of life: 5/20/2024, Latest version: 2.14.18
End of life: 11/6/2023, Latest version: 2.13.13
End of life: 11/6/2023, Latest version: 2.13.13
Red Hat Ansible Tower provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Tower makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.Security Fix(es): Ansible: ansible-tower: Privilege escalation via job isolation escape (CVE-2021-4112) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
End of life: 5/22/2023, Latest version: 2.12.10
End of life: 5/22/2023, Latest version: 2.12.10
Running inventories of ~60k hosts no longer takes a very long time for events to show up Removed artifactdata from data sent to analytics as part of playbookonstats, since artifactdata can contain PII or sensitive data Regular users are no longer experiencing longer load times than a superuser when clicking to edit a job template Updated password validation support to allow modifying password complexity requirements using some Django configurations Fixed AWS inventory tags filtering to support the OR condition Updated Ansible version to 2.9.25 Updated Django version to 2.2.20 Fixed Tower's NGINX Instance vulnerability (CVE-2021-23017)
End of life: 11/7/2022, Latest version: 2.11.12
End of life: 11/7/2022, Latest version: 2.11.12
Security Fix(es): Addressed a security issue which can allow a malicious playbook author to elevate to the awx user from outside the isolated environment: CVE-2021-20253 Upgraded to a more recent version of nginx to address CVE-2019-20372 Upgraded to a more recent version of autobahn to address CVE-2020-35678 Upgraded to a more recent version of jquery to address CVE-2020-11022 and CVE-2020-11023 For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
A few different modules leak sensitive data such as secret values. This could lead in disclosing those credentials for every user which has access to the output of playbook execution.
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucketpipelinevariable module. This flaw allows an attacker to steal bitbucketpipeline credentials. The highest threat from this vulnerability is to confidentiality.
Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) Improved Ansible Tower's web service configuration to allow for processing more simultaneous HTTP(s) requests by default Updated several dependencies of Ansible Tower's User Interface to address (CVE-2020-7720, CVE-2020-7743, CVE-2020-7676) Updated to the latest version of python-psutil to address CVE-2019-18874 Added several optimizations to improve performance for a variety of high-load simultaneous job launch use cases Fixed workflows to no longer prevent certain users from being able to edit approval nodes Fixed confusing behavior for social auth logins across distinct browser tabs Fixed launching of Job Templates that use prompt-at-launch Ansible Vault credentials
Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)
Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)
A flaw was found in Ansible Base when using the awsssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confidentiality.
A flaw was found in Ansible Base when using the awsssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when running multiple ansible processes. This issue affects mainly the service availability.
Fixed an XSS vulnerability (CVE-2020-25626) Fixed the Red Hat sosreport tool to no longer include the Ansible Tower SECRETKEY value Fixed the Ansible Tower installer so that it is now compatible with the latest supported Red Hat OpenShift Container Platforms 3.x and 4.x
<li> Updated to the latest version of the git-python library to no longer cause certain jobs to fail</li> <li> Updated to the latest version of the ovirt.ovirt collection to no longer cause connections to hang when syncing inventory from oVirt/RHV</li> <li> Added a number of optimizations to Ansible Tower's callback receiver to improve the speed of stdout processing for simultaneous playbooks runs</li> <li> Added an optional setting to disable the auto-creation of organizations and teams on successful SAML login</li> <li> Fixed an XSS vulnerability (CVE-2020-25626)</li> <li> Fixed a slow memory leak in the Daphne process</li> <li> Fixed Automation Analytics data gathering to no longer fail for customers with large datasets</li> <li> Fixed scheduled jobs that run every X minute(s) or hour(s) to no longer fail to run at the proper time</li> <li> Fixed delays in Ansible Tower's task manager when large numbers of simultaneous jobs are scheduled</li> <li> Fixed the performance for playbooks that store large amounts of data using the setstats module</li> <li> Fixed the awx-manage removefromqueue tool when used with isolated nodes</li> <li> Fixed an issue that prevented jobs from being properly marked as canceled when Tower is backed up and then restored to another environment</li>