CVE-2019-10156

Name
CVE-2019-10156
Description
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10156
Patch https://github.com/ansible/ansible/pull/57188
Vendor Advisory https://lists.debian.org/debian-lts-announce/2019/09/msg00016.html
Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3744
Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3789
Mailing List https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html
DEBIAN https://www.debian.org/security/2021/dsa-4950

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* ansible >= None < 2.6.18
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* ansible >= 2.7.0 < 2.7.12
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* ansible >= 2.8.0 < 2.8.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status