ansible: Incomplete fix for CVE-2019-10206
Published Nov 26, 2019
7.1
HIGHCVSS 4.0
EPSS 1.66%
Description
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Affected products
- Vendor n/a Product Ansible Defaultn/a
- Version 2.6.20StatusaffectedConstraints-
- Version 2.7.14StatusaffectedConstraints-
- Version 2.8.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible | n/a |
|
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.8.6-1.el7ae
Fixed · RHSA-2019:3207
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.8.6-1.el8ae
Fixed · RHSA-2019:3207
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2019:3201
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.14-1.el7ae
Fixed · RHSA-2019:3202
Red Hat Ansible Engine 2.8 for RHEL 7
ansible-0:2.8.6-1.el7ae
Fixed · RHSA-2019:3203
Red Hat Ansible Engine 2.8 for RHEL 8
ansible-0:2.8.6-1.el8ae
Fixed · RHSA-2019:3203
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2020:0756
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
ansible-0:2.6.20-1.el7ae
Fixed · RHSA-2020:0756
CloudForms Management Engine 5
ansible
Not affected
Red Hat Ceph Storage 2
ansible
Will not fix
Red Hat Ceph Storage 3
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Out of support scope
Red Hat OpenStack Platform 14 (Rocky)
ansible
Will not fix
Red Hat Satellite 6
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.8.6-1.el7ae | Fixed | RHSA-2019:3207 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.8.6-1.el8ae | Fixed | RHSA-2019:3207 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2019:3201 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.14-1.el7ae | Fixed | RHSA-2019:3202 |
| Red Hat Ansible Engine 2.8 for RHEL 7 | ansible-0:2.8.6-1.el7ae | Fixed | RHSA-2019:3203 |
| Red Hat Ansible Engine 2.8 for RHEL 8 | ansible-0:2.8.6-1.el8ae | Fixed | RHSA-2019:3203 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2020:0756 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | ansible-0:2.6.20-1.el7ae | Fixed | RHSA-2020:0756 |
| CloudForms Management Engine 5 | ansible | Not affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Will not fix | n/a |
| Red Hat Ceph Storage 3 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Out of support scope | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | ansible | Will not fix | n/a |
| Red Hat Satellite 6 | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0756 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-14856 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1760829 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14856 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0004 Advisory
- https://github.com/advisories/GHSA-6fq2-x65v-v9h7 Advisory
- https://github.com/ansible/ansible/commit/16684f118715a52e1c46d437652add9ca36423de
- https://github.com/ansible/ansible/commit/2cbd8775ca1271195169f62122df1f88b532e74f
- https://github.com/ansible/ansible/commit/40618d70e61af1123907a5fb246cc4fd35f1e5c3
- https://github.com/ansible/ansible/commit/7f4befdea77045fa83b5f2b304bd5e16b219f74c
- https://github.com/ansible/ansible/pull/63351
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-146.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-14856
- https://www.cve.org/CVERecord?id=CVE-2019-14856
Change history (0)
No recorded changes yet.