ZeroHour

CVE-2019-10206

CVSS 3.1
6.5 medium
EPSS
2%p73
Published
()
Modified
Description

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.

Vendors
redhatdebianopensuse
Products
ansible, debian linux, backports sle, leap
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.