Information disclosure in Ansible - CVE-2019-10156

 

Information disclosure in Ansible - CVE-2019-10156

Published: July 31, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30975
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10156
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.


Affected software

Ansible
ansible (Alpine package)
ansible (Debian package)
ansible
ansible-help
Red Hat Ansible Engine
Red Hat OpenStack Director Deployment Tools
Fedora
openEuler
Red Hat OpenStack
Red Hat OpenStack for IBM Power

How to mitigate CVE-2019-10156

Install update from vendor's website.

Ansible - addressed in versions 2.8.2, 2.6.18-1.el7ae, 2.6.19-1.el7ae, 2.7.12-1.el7ae, 2.8.2-1.el7ae, 2.8.2-1.el8ae
ansible (Alpine package) - update to 2.6.19-r0
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible - update to 2.5.5-3
ansible-help - update to 2.5.5-3
ansible - addressed in versions 2.8.1-1.el7, 2.8.1-1.fc29, 2.8.1-1.fc30

External References

Related Security Bulletins