ZeroHour

CVE-2019-10156

CVSS 3.1
5.4 medium
EPSS
2%p77
Published
()
Modified
Description

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

Vendors
redhatdebian
Products
ansible, openstack, debian linux
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.