CVE-2019-10206Insufficiently Protected Credentials in Redhat Ansible

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 55.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMar 5

Description

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

NVDredhat/ansible2.6.02.6.19+2
PyPIredhat/ansible2.8.02.8.4+2
Debianredhat/ansible< 2.8.6+dfsg-1+3
CVEListV5red_hat/ansibleall 2.6.x before 2.6.19, all 2.7.x before 2.7.13, all 2.8.x before 2.8.4+2
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0

🔴Vulnerability Details

5
GHSA
Ansible password prompts could expose passwords2022-05-24
OSV
Ansible password prompts could expose passwords2022-05-24
GHSA
Ansible password prompts could expose passwords2022-05-24
OSV
CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 22019-11-22
CVEList
CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 22019-11-22

📋Vendor Advisories

4
Ubuntu
Ansible vulnerabilities2025-03-05
Red Hat
ansible: Incomplete fix for CVE-2019-102062019-10-08
Red Hat
Ansible: disclosure data when prompted for password and template characters are passed2019-07-24
Debian
CVE-2019-10206: ansible - ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all ...2019

💬Community

6
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]2019-11-22
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]2019-11-22
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]2019-11-22
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]2019-11-22
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-102062019-10-11
CVE-2019-10206 — Insufficiently Protected Credentials | cvebase