CVE-2019-14856
published 2019-11-26CVE-2019-14856: ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.65%
73.9th percentile
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| redhat | ansible | >= 0 < 2.8.6-r0 | 2.8.6-r0 |
| redhat | ansible | >= 0 < 2.8.6-r0 | 2.8.6-r0 |
| redhat | ansible | >= 0 < 2.8.6-r0 | 2.8.6-r0 |
| redhat | ansible | >= 0 < 2.6.20-r0 | 2.6.20-r0 |
| redhat | ansible | >= 0 < 2.7.14-r0 | 2.7.14-r0 |
| redhat | ansible | >= 2.6.0 < 2.6.20 | 2.6.20 |
| redhat | ansible | >= 2.6.0 < 2.6.20 | 2.6.20 |
| redhat | ansible | >= 2.7.0 < 2.7.14 | 2.7.14 |
| redhat | ansible | >= 2.7.0 < 2.7.14 | 2.7.14 |
| redhat | ansible | >= 2.8.0 < 2.8.6 | 2.8.6 |
| redhat | ansible | >= 2.8.0 < 2.8.6 | 2.8.6 |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ansible password prompts could expose passwords
osv·2022-05-24·CVSS 6.5
CVE-2019-14856 [MEDIUM] Ansible password prompts could expose passwords
Ansible password prompts could expose passwords
A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
This CVE exists due to an incomplete fix for CVE-2019-10206.
GHSA
Ansible password prompts could expose passwords
ghsa·2022-05-24·CVSS 6.5
CVE-2019-14856 [MEDIUM] CWE-287 Ansible password prompts could expose passwords
Ansible password prompts could expose passwords
A data disclosure flaw was found in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
This CVE exists due to an incomplete fix for CVE-2019-10206.
OSV
CVE-2019-14856: ansible before versions 2
osv·2019-11-26·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856: ansible before versions 2
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Red Hat
ansible: Incomplete fix for CVE-2019-10206
vendor_redhat·2019-10-08·CVSS 6.5
CVE-2019-14856 [MEDIUM] CWE-287 ansible: Incomplete fix for CVE-2019-10206
ansible: Incomplete fix for CVE-2019-10206
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
The fix for CVE-2019-10206 was found to be incomplete for the data disclosure flaw in ansible. Password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters as they are not properly wrapped. A password with special characters is exposed starting with the first of these special characters. The highest threat from this vulnerability is to data confidentiality.
Package: ansible (CloudForms Management Engine 5) - Not affected
Package: ansible (Red Hat Ceph Storage 2) - Will not fix
Package: ansible (Red Hat Ceph Storage 3) - Will not fix
Package: ansible (Red Hat OpenStack Platform 10 (Newton)) - Out of support scope
Package: ansibl
Debian
CVE-2019-14856: ansible - ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
vendor_debian·2019·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856: ansible - ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixed by update to 2.8.10 in https://rev
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]
bugzilla·2019-11-22·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206
bugzilla·2019-10-11·CVSS 6.5
CVE-2019-14856 [MEDIUM] CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206
CVE-2019-14856 ansible: Incomplete fix for CVE-2019-10206
The fix made in Ansible for CVE-2019-10206 was not sufficient to resolve the problem.
Discussion:
For reference this is https://github.com/ansible/ansible/pull/63351 upstream.
---
Also note, the backports will be smaller. The fix in devel makes two changes which are independently sufficient to fix the problem. The backport will only include one of them.
---
Vulnerable code from CVE-2019-10206 was included in the version of Ansible shipped with Ceph and Gluster.
Gluster uses Ansible package from Ansible repository and hence it will consume fixes from core Ansible. For Ceph-3 we still maintain Ansible atleast for Ubuntu, Ceph-2 is about to reach end of life in December 2019.
---
This issue has been addressed in the following
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://access.redhat.com/errata/RHSA-2020:0756https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14856http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.htmlhttps://access.redhat.com/errata/RHSA-2020:0756https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14856
2019-11-26
Published