Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY30 SECURITY RECORDS

Red Hat, Inc.

ansible

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at ansible, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2020-14332 11 Sep 2020 2.9.12; 2.8.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-14330 11 Sep 2020 2.10.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-10744 15 May 2020 ansible-engine 2.7.18 and prior; ansible-engine 2.8.12 and prior; ansible-engine 2.9.9 and prior; ansible-tower 3.4.5 and prior; ansible-tower 3.5.6 and prior; ansible-tower 3.6.4 and prior No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1746 12 May 2020 ansible-engine versions 2.7.x before 2.7.17; ansible-engine versions 2.8.x before 2.8.11; ansible-engine versions 2.9.x before 2.9.7; Ansible Tower <= 3.4.5; Ansible Tower <= 3.5.5; Ansible Tower <= 3.6.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-10685 11 May 2020 ansible-engine versions 2.7.x before 2.7.17; ansible-engine 2.8.x before 2.8.11; ansible-engine 2.9.x before 2.9.7; Ansible Tower <= 3.4.5; Ansible Tower <= 3.5.5; Ansible Tower <= 3.6.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-10691 30 Apr 2020 all ansible-engine versions 2.9.x prior to 2.9.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-14905 31 Mar 2020 2.9.x before 2.9.3; 2.8.x before 2.8.8; 2.7.x before 2.7.16; 2.7.x and earlier An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-10684 24 Mar 2020 all Ansible 2.7.x versions prior to 2.7.17; all Ansible 2.8.x versions prior to 2.8.9; all Ansible 2.9.x versions prior to 2.9.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1738 16 Mar 2020 2.7.x, 2.8.x, 2.9.x No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1740 16 Mar 2020 2.7.x, 2.8.x, 2.9.x No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1735 16 Mar 2020 2.7.x, 2.8.x, 2.9.x An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-1736 16 Mar 2020 2.7.x, 2.8.x, 2.9.x No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1753 16 Mar 2020 all Ansible 2.7.x versions prior to 2.7.17; all Ansible 2.8.x versions prior to 2.8.11; all Ansible 2.9.x versions prior to 2.9.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-1739 12 Mar 2020 2.7.16 and prior; 2.8.8 and prior; 2.9.5 and prior An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-1733 11 Mar 2020 2.7.17 and prior; 2.8.9 and prior; 2.9.6 and prior No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1737 9 Mar 2020 2.7.17 and prior; 2.8.9 and prior; 2.9.6 and prior; fixed in 2.10 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1734 3 Mar 2020 n/a No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-14864 2 Jan 2020 Ansible versions 2.9.x before 2.9.1; Ansible versions 2.8.x before 2.8.7; Ansible versions 2.7.x before 2.7.15 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-10217 25 Nov 2019 ansible 2.8.0 before 2.8.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-10206 22 Nov 2019 all 2.8.x before 2.8.4; all 2.7.x before 2.7.13; all 2.6.x before 2.6.19 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-14858 14 Oct 2019 ansible_engine-2.x up to 2.8; ansible_tower-3.x up to 3.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-14846 8 Oct 2019 all ansible_engine-2.x and ansible_engine-3.x up to ansible_engine-3.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-10156 30 Jul 2019 fixed in 2.6.18; fixed in 2.7.12; fixed in 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-3828 27 Mar 2019 2.5.15; 2.6.14; 2.7.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-16876 3 Jan 2019 before 2.5.14; before 2.6.11; before 2.7.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2018-16859 29 Nov 2018 2.8 and older An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2016-8614 31 Jul 2018 2.2.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2016-8628 31 Jul 2018 2.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2016-8647 26 Jul 2018 2.2.1.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-7550 21 Nov 2017 2.3.x before 2.3.3, 2.4.x before 2.4.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.