Lucene search

K
cvelistRedhatCVELIST:CVE-2019-10156
HistoryJul 30, 2019 - 10:12 p.m.

CVE-2019-10156

2019-07-3022:12:30
CWE-200
redhat
www.cve.org
1

4.6 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.3%

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

CNA Affected

[
  {
    "product": "ansible",
    "vendor": "Red Hat",
    "versions": [
      {
        "status": "affected",
        "version": "fixed in 2.6.18"
      },
      {
        "status": "affected",
        "version": "fixed in 2.7.12"
      },
      {
        "status": "affected",
        "version": "fixed in 2.8.2"
      }
    ]
  }
]

4.6 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.3%