cbcvebase.
CVE-2019-10206
published 2019-11-22

CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding…

PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.50%
71.6th percentile
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 2.8.6+dfsg-1 (bookworm)ansible 2.8.6+dfsg-1 (bookworm)
debiandebian_linux
opensusebackports_sle
opensuseleap
red_hatansible
red_hatansible
red_hatansible
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 2.8.6+dfsg-12.8.6+dfsg-1
redhatansible>= 0 < 1.5.4+dfsg-1ubuntu0.1~esm31.5.4+dfsg-1ubuntu0.1~esm3
redhatansible>= 0 < 2.0.0.2-2ubuntu1.3+esm62.0.0.2-2ubuntu1.3+esm6
redhatansible>= 0 < 2.0.0.2-2ubuntu1.3+esm52.0.0.2-2ubuntu1.3+esm5
redhatansible>= 0 < 2.5.1+dfsg-1ubuntu0.1+esm52.5.1+dfsg-1ubuntu0.1+esm5
redhatansible>= 0 < 2.9.6+dfsg-1ubuntu0.1~esm32.9.6+dfsg-1ubuntu0.1~esm3
redhatansible>= 2.6.0 < 2.6.192.6.19
redhatansible>= 2.6.0 < 2.6.192.6.19
redhatansible>= 2.6.0 < 2.6.202.6.20
redhatansible>= 2.7.0 < 2.7.132.7.13
redhatansible>= 2.7.0 < 2.7.132.7.13
redhatansible>= 2.7.0 < 2.7.142.7.14
redhatansible>= 2.8.0 < 2.8.42.8.4
redhatansible>= 2.8.0 < 2.8.42.8.4
redhatansible>= 2.8.0 < 2.8.62.8.6

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.