CVE-2019-10156
Publication date 30 July 2019
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ansible | ||
| 18.04 LTS bionic |
Fixed 2.5.1+dfsg-1ubuntu0.1
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.4 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
References
Related Ubuntu Security Notices (USN)
- USN-4072-1
- Ansible vulnerabilities
- 24 July 2019