VulnerabilityModified
CVE-2019-10206
Passwords should be wrapped to prevent templates trigger and exposing them.
MEDIUM 6.5EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- redhat/ansible · debian/debian linux · opensuse/backports sle · opensuse/leap
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10206Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10206Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
- https://www.debian.org/security/2021/dsa-4950Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.