CVE-2019-10206
published 2019-11-22CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding…
PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.50%
71.6th percentile
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.8.6+dfsg-1 (bookworm) | ansible 2.8.6+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 2.8.6+dfsg-1 | 2.8.6+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.4+dfsg-1ubuntu0.1~esm3 | 1.5.4+dfsg-1ubuntu0.1~esm3 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm6 | 2.0.0.2-2ubuntu1.3+esm6 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm5 | 2.0.0.2-2ubuntu1.3+esm5 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1+esm5 | 2.5.1+dfsg-1ubuntu0.1+esm5 |
| redhat | ansible | >= 0 < 2.9.6+dfsg-1ubuntu0.1~esm3 | 2.9.6+dfsg-1ubuntu0.1~esm3 |
| redhat | ansible | >= 2.6.0 < 2.6.19 | 2.6.19 |
| redhat | ansible | >= 2.6.0 < 2.6.19 | 2.6.19 |
| redhat | ansible | >= 2.6.0 < 2.6.20 | 2.6.20 |
| redhat | ansible | >= 2.7.0 < 2.7.13 | 2.7.13 |
| redhat | ansible | >= 2.7.0 < 2.7.13 | 2.7.13 |
| redhat | ansible | >= 2.7.0 < 2.7.14 | 2.7.14 |
| redhat | ansible | >= 2.8.0 < 2.8.4 | 2.8.4 |
| redhat | ansible | >= 2.8.0 < 2.8.4 | 2.8.4 |
| redhat | ansible | >= 2.8.0 < 2.8.6 | 2.8.6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ansible regression
osv·2025-03-28·CVSS 4.3
[MEDIUM] ansible regression
ansible regression
USN-7330-1 fixed vulnerabilities in Ansible. The update introduced a
regression when attempting to install Ansible on Ubuntu 16.04 LTS.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible did not properly verify certain fields
of X.509 certificates. An attacker could possibly use this issue to
spoof SSL servers if they were able to intercept network communications.
This issue only affected Ubuntu 14.04 LTS. (CVE-2015-3908)
Martin Carpenter discovered that certain connection plugins for Ansible
did not properly restrict users. An attacker with local access could
possibly use this issue to escape a restricted environment via symbolic
links misuse. This issue only affected Ubuntu 14.04 LTS. (CVE-2
OSV
ansible vulnerabilities
osv·2025-03-05·CVSS 4.3
CVE-2015-3908 [MEDIUM] ansible vulnerabilities
ansible vulnerabilities
It was discovered that Ansible did not properly verify certain fields of
X.509 certificates. An attacker could possibly use this issue to spoof
SSL servers if they were able to intercept network communications. This
issue only affected Ubuntu 14.04 LTS. (CVE-2015-3908)
Martin Carpenter discovered that certain connection plugins for Ansible
did not properly restrict users. An attacker with local access could
possibly use this issue to escape a restricted environment via symbolic
links misuse. This issue only affected Ubuntu 14.04 LTS. (CVE-2015-6240)
Robin Schneider discovered that Ansible's apt_key module did not properly
verify key fingerprints. A remote attacker could possibly use this issue
to perform key injection, leading to the access of sensitive informati
GHSA
Ansible password prompts could expose passwords
ghsa·2022-05-24
CVE-2019-10206 [HIGH] CWE-20 Ansible password prompts could expose passwords
Ansible password prompts could expose passwords
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
OSV
Ansible password prompts could expose passwords
osv·2022-05-24
CVE-2019-10206 [HIGH] Ansible password prompts could expose passwords
Ansible password prompts could expose passwords
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
OSV
Ansible password prompts could expose passwords
osv·2022-05-24·CVSS 6.5
CVE-2019-14856 [MEDIUM] Ansible password prompts could expose passwords
Ansible password prompts could expose passwords
A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
This CVE exists due to an incomplete fix for CVE-2019-10206.
GHSA
Ansible password prompts could expose passwords
ghsa·2022-05-24·CVSS 6.5
CVE-2019-14856 [MEDIUM] CWE-287 Ansible password prompts could expose passwords
Ansible password prompts could expose passwords
A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
This CVE exists due to an incomplete fix for CVE-2019-10206.
OSV
CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2
osv·2019-11-22·CVSS 6.5
CVE-2019-10206 [MEDIUM] CVE-2019-10206: ansible-playbook -k and ansible cli tools, all versions 2
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Ubuntu
Ansible regression
vendor_ubuntu·2025-03-28·CVSS 4.3
[MEDIUM] Ansible regression
Title: Ansible regression
Summary: USN 7330-1 introduced a regression in Ansible.
USN-7330-1 fixed vulnerabilities in Ansible. The update introduced a
regression when attempting to install Ansible on Ubuntu 16.04 LTS.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible did not properly verify certain fields
of X.509 certificates. An attacker could possibly use this issue to
spoof SSL servers if they were able to intercept network communications.
This issue only affected Ubuntu 14.04 LTS. (CVE-2015-3908)
Martin Carpenter discovered that certain connection plugins for Ansible
did not properly restrict users. An attacker with local access could
possibly use this issue to escape a restricted environment via symbolic
Ubuntu
Ansible vulnerabilities
vendor_ubuntu·2025-03-05·CVSS 4.3
CVE-2019-14904 [MEDIUM] Ansible vulnerabilities
Title: Ansible vulnerabilities
Summary: Several security issues were fixed in Ansible.
It was discovered that Ansible did not properly verify certain fields of
X.509 certificates. An attacker could possibly use this issue to spoof
SSL servers if they were able to intercept network communications. This
issue only affected Ubuntu 14.04 LTS. (CVE-2015-3908)
Martin Carpenter discovered that certain connection plugins for Ansible
did not properly restrict users. An attacker with local access could
possibly use this issue to escape a restricted environment via symbolic
links misuse. This issue only affected Ubuntu 14.04 LTS. (CVE-2015-6240)
Robin Schneider discovered that Ansible's apt_key module did not properly
verify key fingerprints. A remote attacker could possibly use this issue
to per
Red Hat
ansible: Incomplete fix for CVE-2019-10206
vendor_redhat·2019-10-08·CVSS 6.5
CVE-2019-14856 [MEDIUM] CWE-287 ansible: Incomplete fix for CVE-2019-10206
ansible: Incomplete fix for CVE-2019-10206
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
The fix for CVE-2019-10206 was found to be incomplete for the data disclosure flaw in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
Package: ansible (CloudForms Management Engine 5) - Not affected
Package: ansible (Red Hat Ceph Storage 2) - Will not fix
Package: ansible (Red Hat Ceph Storage 3) - Will not fix
Package: ansible (Red Hat OpenStack Platform 10 (Newton)) - Out of support scope
Package: ansibl
Red Hat
Ansible: disclosure data when prompted for password and template characters are passed
vendor_redhat·2019-07-24·CVSS 6.5
CVE-2019-10206 [MEDIUM] CWE-522 Ansible: disclosure data when prompted for password and template characters are passed
Ansible: disclosure data when prompted for password and template characters are passed
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
Package: ansible (Red Hat Ceph Storage 2) - Out of support
Debian
CVE-2019-10206: ansible - ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all ...
vendor_debian·2019·CVSS 6.5
CVE-2019-10206 [MEDIUM] CVE-2019-10206: ansible - ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all ...
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Scope: local
bookworm: resolved (fixed in 2.8.6+dfsg-1)
bullseye: resolved (fixed in 2.8.6+dfsg-1)
forky: resolved (fixed in 2.8.6+dfsg-1)
sid: resolved (fixed in 2.8.6+dfsg-1)
trixie: resolved (fixed in 2.8.6+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by update to 2.8.10 in https://rev
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206
bugzilla·2019-10-11·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206
The fix made in Ansible for CVE-2019-10206 was not sufficient to resolve the problem.
Discussion:
For reference this is https://github.com/ansible/ansible/pull/63351 upstream.
---
Also note, the backports will be smaller. The fix in devel makes two changes which are independently sufficient to fix the problem. The backport will only include one of them.
---
Vulnerable code from CVE-2019-10206 was included in the version of Ansible shipped with Ceph and Gluster.
Gluster uses Ansible package from Ansible repository and hence it will consume fixes from core Ansible. For Ceph-3 we still maintain Ansible atleast for Ubuntu, Ceph-2 is about to reach end of life in December 2019.
---
This issue has been addressed in the following
Bugzilla
CVE-2019-10206 Ansible: disclosure data when prompted for password and template characters are passed
bugzilla·2019-07-23·CVSS 6.5
CVE-2019-10206 [MEDIUM] CVE-2019-10206 Ansible: disclosure data when prompted for password and template characters are passed
CVE-2019-10206 Ansible: disclosure data when prompted for password and template characters are passed
ansible-playbook -k and ansible cli tools prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Discussion:
Acknowledgments:
Name: Paul Rubin
---
Fix got merged into development https://github.com/ansible/ansible/pull/59246
backports:
2.8.x https://github.com/ansible/ansible/pull/59552
2.7.x https://github.com/ansible/ansible/pull/59553
2.6.x https://github.com/ansible/ansible/pull/59554
---
This issue has been addressed in the following products:
Red Hat Ansible Engine 2.7 for RHEL 7
Via RHSA-2019:2544 https://access.redhat.com/errata/RHSA-2019:2544
---
This issue
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10206https://lists.debian.org/debian-lts-announce/2023/12/msg00018.htmlhttps://www.debian.org/security/2021/dsa-4950http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10206https://lists.debian.org/debian-lts-announce/2023/12/msg00018.htmlhttps://www.debian.org/security/2021/dsa-4950
2019-11-22
Published