CVE-2019-10156
Summary
| CVE | CVE-2019-10156 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-30 23:15:00 UTC |
| Updated | 2022-04-19 15:36:00 UTC |
| Description | A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| [SECURITY] [DLA 2535-1] ansible security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1923-1] ansible security update |
MLIST |
lists.debian.org |
Vendor Advisory |
| 1717311 – (CVE-2019-10156) CVE-2019-10156 ansible: unsafe template evaluation of returned module data can lead to information disclosure |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Vendor Advisory |
| Debian -- Security Information -- DSA-4950-1 ansible |
DEBIAN |
www.debian.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| safe_eval fix by bcoca · Pull Request #57188 · ansible/ansible · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178744 Debian Security Update for ansible (DSA 4950-1)
- 500003 Alpine Linux Security Update for ansible
- 501344 Alpine Linux Security Update for ansible-base
- 981347 Python (pip) Security Update for ansible (GHSA-grgm-pph5-j5h7)