CVE-2019-10206 describes a password exposure vulnerability affecting ansible-playbook -k and other Ansible CLI tools across versions 2.8.x (before 2.8.4), 2.7.x (before 2.7.13), and 2.6.x (before 2.6.19), impacting Debian, openSUSE, and Red Hat distributions. The vulnerability allows passwords containing special characters to be expanded from templates, potentially exposing them if not properly wrapped. With a CVSS score of 6.5 (Medium), this issue presents a high confidentiality impact with low attack complexity, requiring low privileges and no user interaction. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.0, < 2.6.19CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.13CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.4CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.