SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10206

Passwords should be wrapped to prevent templates trigger and exposing them.

MEDIUM 6.5EPSS 1.52%

Does this matter?

Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.

Description

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.52% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
redhat/ansible · debian/debian linux · opensuse/backports sle · opensuse/leap
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.