CVE-2019-10206
Summary
| CVE | CVE-2019-10206 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-22 13:15:00 UTC |
| Updated | 2023-12-28 19:15:00 UTC |
| Description | ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2020:0513-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] [DLA 3695-1] ansible security update |
|
lists.debian.org |
|
| [security-announce] openSUSE-SU-2020:0523-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Debian -- Security Information -- DSA-4950-1 ansible |
DEBIAN |
www.debian.org |
|
| 1732623 – (CVE-2019-10206) CVE-2019-10206 Ansible: disclosure data when prompted for password and template characters are passed |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178744 Debian Security Update for ansible (DSA 4950-1)
- 500004 Alpine Linux Security Update for ansible
- 501345 Alpine Linux Security Update for ansible-base
- 6000405 Debian Security Update for ansible (DLA 3695-1)