VulnerabilityModified
CVE-2019-10156
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution.
MEDIUM 5.4EPSS 1.77%
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/ansible · redhat/openstack · debian/debian linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2019:3744Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3789Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10156Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/pull/57188Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00016.htmlVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3744Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3789Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10156Issue Tracking, Vendor Advisory
- https://github.com/ansible/ansible/pull/57188Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00016.htmlVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.