Input validation error in Ansible - CVE-2019-10206
Published: November 22, 2019 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to gain access to sensitive information.
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Affected software
ansible (Alpine package)
ansible (Debian package)
ansible
Red Hat Ansible Engine
Red Hat OpenStack Director Deployment Tools
Fedora
SUSE Linux
Opensuse
Red Hat OpenStack
Red Hat OpenStack for IBM Power
How to mitigate CVE-2019-10206
ansible (Alpine package) - update to 2.4.6.0-r1
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible - addressed in versions 2.8.4-1.el7, 2.8.4-1.fc30, 2.9.3-1.el7, 2.9.3-1.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Ansible
- OpenSUSE Linux update for SUSE Manager Client Tools
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- Input validation error in ansible (Alpine package)
- Debian update for ansible
- Ansible Engine 2.8 update for Ansible
- Ansible Engine 2.8 update for Ansible
- Ansible Engine 2.7 update for Ansible
- Ansible Engine 2.6 update for Ansible
- Red Hat OpenStack Platform 14 update for ansible
- Red Hat OpenStack Platform 13 update for ansible
- Red Hat OpenStack Platform 13 update for ansible
- Fedora 30 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora EPEL 8 update for ansible