Vulnerability CVE-2019-10156: Information

Description

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

Severity: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Published: July 31, 2019
Modified: April 19, 2022
Error type identifier: CWE-200

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
ansiblep102.8.4-alt12.9.27-alt3.p10.2ALT-PU-2019-2615-1237059Fixed
ansiblep92.8.10-alt12.9.27-alt1ALT-PU-2020-1490-1247670Fixed
ansiblec10f12.8.4-alt12.9.27-alt3.p10.1ALT-PU-2019-2615-1237059Fixed
ansiblec9f22.9.21-alt12.9.26-alt2ALT-PU-2021-1800-1271383Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
      Start including
      2.8.0
      End excliding
      2.8.2

      cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
      Start including
      2.7.0
      End excliding
      2.7.12

      cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
      End excliding
      2.6.18

      Configuration 2

      cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*