All security vulnerability reports MUST be submitted by email to: security@ansible.com
Security vulnerabilities MUST NOT be reported through public channels such as GitHub issues, pull requests, the Ansible Forum, or social media.
When submitting a vulnerability report, include the following:
- Title (required): Clear, concise, descriptive summary.
- Impacted project (required): Ideally a link to the GitHub project.
- Reporter details (optional): Your name or handle and affiliation.
- Vulnerability description (required): Technical details of the issue.
- Affected versions (required): Known affected version(s), and ideally all affected versions.
- Reproduction steps (required): Minimal example to reproduce the issue.
- Impact assessment (required): Potential exploit scenarios and severity.
- Suggested fix (optional): Proposed remediation, if any.
- Disclosure status (required): Whether this has been shared with other parties or published and your plan for future sharing (e.g., at a conference).
- The Ansible Security Team aims to confirm receipt of vulnerability reports within one (1) business day.
- Our goal is to assess the report, coordinate fix and disclosure as quickly as possible.
- All confirmed vulnerabilities are addressed according to severity and impact.
Generally, only the latest release of this project receives security updates. Earlier versions may receive critical fixes on a best-effort basis.
For the complete Ansible Security Policy, including what qualifies as a reportable vulnerability, severity classification, the response process, coordinated disclosure, and the vulnerability management process, see ansible.com/security.
This project is stewarded by Red Hat, Inc., an open-source software steward as defined in Article 3(14) of the EU Cyber Resilience Act (Regulation 2024/2847).
Contact: cra-steward@redhat.com