ansible: unsafe template evaluation of returned module data can lead to information disclosure
Published Jul 30, 2019
5.3
MEDIUMCVSS 4.0
EPSS 1.77%
Description
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Affected products
-
- Version fixed in 2.6.18StatusaffectedConstraints-
- Version fixed in 2.7.12StatusaffectedConstraints-
- Version fixed in 2.8.2StatusaffectedConstraints-
- Version
Configuration 1
Configuration 3
- 8.0
- 9.0
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.8.2-1.el7ae
Fixed · RHSA-2019:1706
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.8.2-1.el8ae
Fixed · RHSA-2019:1706
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.18-1.el7ae
Fixed · RHSA-2019:1707
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.12-1.el7ae
Fixed · RHSA-2019:1705
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.2-1.el7ae
Fixed · RHSA-2019:1708
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.2-1.el8ae
Fixed · RHSA-2019:1708
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:3789
Red Hat OpenStack Platform 14.0 (Rocky)
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:3744
CloudForms Management Engine 5
ansible
Out of support scope
Red Hat Ansible Tower 3
ansible
Affected
Red Hat Ceph Storage 2
ansible
Will not fix
Red Hat Ceph Storage 3
ansible
Affected
Red Hat Enterprise Linux 7
ansible
Will not fix
Red Hat OpenShift Container Platform 3.2
ansible
Out of support scope
Red Hat OpenShift Container Platform 3.3
ansible
Out of support scope
Red Hat OpenShift Container Platform 3.4
ansible
Out of support scope
Red Hat OpenShift Container Platform 3.5
ansible
Out of support scope
Red Hat OpenShift Container Platform 3.6
ansible
Out of support scope
Red Hat OpenShift Container Platform 3.7
ansible
Out of support scope
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.8.2-1.el7ae | Fixed | RHSA-2019:1706 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.8.2-1.el8ae | Fixed | RHSA-2019:1706 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.18-1.el7ae | Fixed | RHSA-2019:1707 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.12-1.el7ae | Fixed | RHSA-2019:1705 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.2-1.el7ae | Fixed | RHSA-2019:1708 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.2-1.el8ae | Fixed | RHSA-2019:1708 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:3789 |
| Red Hat OpenStack Platform 14.0 (Rocky) | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:3744 |
| CloudForms Management Engine 5 | ansible | Out of support scope | n/a |
| Red Hat Ansible Tower 3 | ansible | Affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Will not fix | n/a |
| Red Hat Ceph Storage 3 | ansible | Affected | n/a |
| Red Hat Enterprise Linux 7 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.2 | ansible | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.3 | ansible | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.4 | ansible | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.5 | ansible | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.6 | ansible | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.7 | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
AV:N/AC:L/Au:S/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.77% (0.01774) | 77.37th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.76% (0.01759) | 74.99th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.36% (0.00359) | 55.98th | v4 (v2025.03.14) |
| Dec 17, 2024 | 0.37% (0.00369) | 72.25th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.31% (0.00314) | 69.41th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.32% (0.00318) | 66.69th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.33% (0.00332) | 66.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.03% (0.01034) | 37.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.00% (0.14004) | 90.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.04% (0.07038) | 83.71th | v1 |
| Jan 6, 2022 | 7.04% (0.07038) | 83.55th | v1 |
| Oct 11, 2021 | 1.66% (0.01659) | 74.32th | v1 |
| Oct 10, 2021 | 7.04% (0.07038) | 91.14th | v1 |
| Aug 8, 2021 | 7.04% (0.07038) | 0.00th | v1 |
| Aug 7, 2021 | 1.45% (0.01454) | 0.00th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.45% (0.01454) | 0.00th | v1 |
References (16)
- https://access.redhat.com/errata/RHSA-2019:3744 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2019:3789 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-10156 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1717311 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10156 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-grgm-pph5-j5h7 Advisory
- https://github.com/ansible/ansible/commit/04e94274fb92e116e9082cc9b86b1fd05c836922
- https://github.com/ansible/ansible/commit/3ff6505e8ff0e4655bab008886983476ef903375
- https://github.com/ansible/ansible/commit/a11c3edfa41e7e4a4db323cdabfc2eae1b61da2a
- https://github.com/ansible/ansible/pull/57188 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-2.yaml
- https://lists.debian.org/debian-lts-announce/2019/09/msg00016.html mailing-listx_refsource_MLISTVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00023.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10156
- https://www.cve.org/CVERecord?id=CVE-2019-10156
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.