CVE-2019-10156

Source
https://cve.org/CVERecord?id=CVE-2019-10156
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10156.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10156
Aliases
Downstream
Related
Published
2019-07-30T23:15:12.043Z
Modified
2026-02-04T21:34:28.838388Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

References

Affected packages

Git / github.com/ansible/ansible

Affected versions

v2.*
v2.7.0
v2.7.1
v2.7.10
v2.7.11
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.7.6
v2.7.7
v2.7.8
v2.7.9
v2.8.0
v2.8.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10156.json"