#VU30975 Information disclosure in Ansible - CVE-2019-10156
Published: July 31, 2019 / Updated: July 17, 2020
Ansible
Red Hat Inc.
Description
The vulnerability allows a remote authenticated user to read and manipulate data.
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.