CVE-2019-10156
moderate-risk
Published 2019-07-30
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Do I need to act?
-
0.50% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.4/10
Medium
NETWORK
/ LOW complexity
Affected Products (5)
References (14)
Vendor Advisory
https://access.redhat.com/errata/RHSA-2019:3744
Vendor Advisory
https://access.redhat.com/errata/RHSA-2019:3789
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10156
Third Party Advisory
https://www.debian.org/security/2021/dsa-4950
Vendor Advisory
https://access.redhat.com/errata/RHSA-2019:3744
Vendor Advisory
https://access.redhat.com/errata/RHSA-2019:3789
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10156
Third Party Advisory
https://www.debian.org/security/2021/dsa-4950
35
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
2/34 · Minimal
Exposure
12/34 · Low