Information disclosure in Ansible - CVE-2019-10156
Published: July 31, 2019 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to read and manipulate data.
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Affected software
ansible (Alpine package)
ansible (Debian package)
ansible
ansible-help
Red Hat Ansible Engine
Red Hat OpenStack Director Deployment Tools
Fedora
openEuler
Red Hat OpenStack
Red Hat OpenStack for IBM Power
How to mitigate CVE-2019-10156
ansible (Alpine package) - update to 2.6.19-r0
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible - update to 2.5.5-3
ansible-help - update to 2.5.5-3
ansible - addressed in versions 2.8.1-1.el7, 2.8.1-1.fc29, 2.8.1-1.fc30
External References
Related Security Bulletins
- Information disclosure in Ansible
- Information disclosure in ansible (Alpine package)
- Debian update for ansible
- Ansible Engine 2.7 update for ansible
- Ansible Engine 2.8 update for ansible
- Ansible Engine 2.6 update for ansible
- Ansible Engine 2.8 update for ansible
- Red Hat OpenStack Platform 14 update for ansible
- Red Hat OpenStack Platform 13 update for ansible
- openEuler update for ansible
- Fedora EPEL 7 update for ansible
- Fedora 29 update for ansible
- Fedora 30 update for ansible