CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2019-10156 — MEDIUM severity vulnerability | Release Alert
CVE-2019-10156
5.4
MEDIUMCVSS v3
Published
July 30, 2019
CVSS v2
5.5 MEDIUM
Affected
2 projects
Assigned by
Red Hat
Severity scale
010
Description
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
GitHubAnsible is a radically simple IT automation platform that makes your applications and systems easier to deploy and maintain. Automate everything from code deployment to network configuration to cloud management, in a language that approaches plain English, using SSH, with no agents to install on remote systems. https://docs.ansible.com.