Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10206

Опубликовано: 22 нояб. 2019
Источник: debian

Описание

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.8.6+dfsg-1package
ansibleend-of-lifestretchpackage
ansiblenot-affectedjessiepackage

Примечания

  • https://github.com/ansible/ansible/pull/59246

  • 2.8.x https://github.com/ansible/ansible/pull/59552

  • 2.7.x https://github.com/ansible/ansible/pull/59553

  • 2.6.x https://github.com/ansible/ansible/pull/59554

  • When fixing this issue is needed to make the fix complete with

  • https://github.com/ansible/ansible/pull/63351 to not open

  • CVE-2019-14856.

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS3: 6.4
redhat
около 7 лет назад

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS3: 6.5
nvd
почти 7 лет назад

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS3: 6.5
github
больше 4 лет назад

Ansible password prompts could expose passwords

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации