CVE-2019-10156: Infoleak
[ansiblepassword] in the ~/.ssh/authorizedkeys file is repalced by administrator's password on remote node by templating.
Upstream pull:
https://github.com/ansible/ansible/pull/57188
Other sources
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in Ansible templating?
The vulnerability ID for this flaw in Ansible templating is CVE-2019-10156.
What is the severity of CVE-2019-10156?
The severity of CVE-2019-10156 is medium (severity value of 4).
Which versions of Ansible are affected by CVE-2019-10156?
Versions before 2.6.18, 2.7.12, and 2.8.2 of Ansible are affected by CVE-2019-10156.
How can an attacker exploit the vulnerability in CVE-2019-10156?
An attacker can exploit the vulnerability in CVE-2019-10156 by taking advantage of unintended variable substitution, which can lead to information disclosure.
Is there a fix available for CVE-2019-10156?
Yes, the fix for CVE-2019-10156 is available in Ansible versions 2.6.18, 2.7.12, and 2.8.2.