Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21694
HistoryOct 14, 2019 - 7:06 a.m.

Information Disclosure

2019-10-1407:06:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.002 Low

EPSS

Percentile

60.2%

ansible is vulnerable to information disclosure. The attack is possible due to an incomplete fix of CVE-2019-10206 which does not perform safe type conversions using AnsibleUnsafeBytes and AnsibleUnsafeBytes classes, allowing CLI provided passwords being incorrectly templated when using to_text, to_bytes, or to_native during post processing of PlayContext.