Exposure of Sensitive Information to an Unauthorized Actor in ansible
Moderate severity
GitHub Reviewed
Published
Jul 31, 2019
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Package
Affected versions
< 2.6.18
>= 2.7.0a1, < 2.7.12
>= 2.8.0a1, < 2.8.2
Patched versions
2.6.18
2.7.12
2.8.2
Description
Published by the National Vulnerability Database
Jul 30, 2019
Reviewed
Jul 31, 2019
Published to the GitHub Advisory Database
Jul 31, 2019
Last updated
Sep 4, 2024
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
References