Input validation error in Ansible - CVE-2019-14856

 

Input validation error in Ansible - CVE-2019-14856

Published: November 26, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30577
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14856
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None


Affected software

Ansible
ansible (Alpine package)
ansible
Fedora
SUSE Linux
Opensuse
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Red Hat OpenStack Director Deployment Tools

How to mitigate CVE-2019-14856

Install update from vendor's website.

Ansible - addressed in versions 2.8.6, 2.6.20-1.el7ae
ansible (Alpine package) - update to 2.6.20-r0
ansible - addressed in versions 2.9.3-1.el7, 2.9.3-1.el8

External References

Related Security Bulletins