A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1923-1 ansible security update
Debian DLA Debian DLA DLA-2535-1 ansible security update
Debian DSA Debian DSA DSA-4950-1 ansible security update
EUVD EUVD EUVD-2019-0006 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Github GHSA Github GHSA GHSA-grgm-pph5-j5h7 Exposure of Sensitive Information to an Unauthorized Actor in ansible
Ubuntu USN Ubuntu USN USN-4072-1 Ansible vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T22:10:09.972Z

Reserved: 2019-03-27T00:00:00

Link: CVE-2019-10156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-30T23:15:12.043

Modified: 2024-11-21T04:18:32.160

Link: CVE-2019-10156

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-06-04T00:00:00Z

Links: CVE-2019-10156 - Bugzilla

cve-icon OpenCVE Enrichment

No data.