Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-10206

Опубликовано: 22 нояб. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 6.5

Описание

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

2.8.6+dfsg-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps-legacy/xenial

released

2.0.0.2-2ubuntu1.3+esm5
esm-apps/bionic

released

2.5.1+dfsg-1ubuntu0.1+esm5
esm-apps/focal

not-affected

2.8.6+dfsg-1
esm-apps/jammy

not-affected

2.8.6+dfsg-1
esm-apps/noble

not-affected

2.8.6+dfsg-1
esm-apps/xenial

released

2.0.0.2-2ubuntu1.3+esm5

Показывать по

EPSS

Процентиль: 73%
0.01515
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
redhat
около 7 лет назад

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS3: 6.5
nvd
почти 7 лет назад

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

CVSS3: 6.5
debian
почти 7 лет назад

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2 ...

CVSS3: 6.5
github
больше 4 лет назад

Ansible password prompts could expose passwords

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость системы управления конфигурациями Ansible, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 73%
0.01515
Низкий

4 Medium

CVSS2

6.5 Medium

CVSS3

Уязвимость CVE-2019-10206