Ansible: disclosure data when prompted for password and template characters are passed
Published Nov 22, 2019
7.1
HIGHCVSS 4.0
EPSS 1.52%
Description
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Affected products
-
- Version all 2.6.x before 2.6.19StatusaffectedConstraints-
- Version all 2.7.x before 2.7.13StatusaffectedConstraints-
- Version all 2.8.x before 2.8.4StatusaffectedConstraints-
- Version
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.8.4-1.el7ae
Fixed · RHSA-2019:2543
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.8.4-1.el8ae
Fixed · RHSA-2019:2543
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:2545
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.13-1.el7ae
Fixed · RHSA-2019:2544
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.4-1.el7ae
Fixed · RHSA-2019:2542
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.4-1.el8ae
Fixed · RHSA-2019:2542
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:3789
Red Hat OpenStack Platform 14.0 (Rocky)
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:3744
Red Hat Ceph Storage 2
ansible
Out of support scope
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.8.4-1.el7ae | Fixed | RHSA-2019:2543 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.8.4-1.el8ae | Fixed | RHSA-2019:2543 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:2545 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.13-1.el7ae | Fixed | RHSA-2019:2544 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.4-1.el7ae | Fixed | RHSA-2019:2542 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.4-1.el8ae | Fixed | RHSA-2019:2542 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:3789 |
| Red Hat OpenStack Platform 14.0 (Rocky) | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:3744 |
| Red Hat Ceph Storage 2 | ansible | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html vendor-advisoryMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-10206 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1732623 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10206 Issue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0003 Advisory
- https://github.com/advisories/GHSA-cqmr-rcpr-cxh3 Advisory
- https://github.com/ansible/ansible/commit/4b5aed4e5af4c7aab621662f50a289e99b8ac393
- https://github.com/ansible/ansible/commit/d39488ece44956f6a169a498b067bbef54552be1
- https://github.com/ansible/ansible/commit/d728127310b4f3a40ce8b9df3affb88ffaeea073
- https://github.com/ansible/ansible/pull/59246
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-145.yaml
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2019-10206
- https://www.cve.org/CVERecord?id=CVE-2019-10206
- https://www.debian.org/security/2021/dsa-4950 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.