{"schema_version":"1.9.0","id":"GHSA-cqmr-rcpr-cxh3","published":"2022-05-24T17:01:46Z","modified":"2024-11-25T05:23:22.828959Z","aliases":["CVE-2019-10206","PYSEC-2019-145"],"summary":"Ansible password prompts could expose passwords","details":"ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.","affected":[{"package":{"name":"ansible","ecosystem":"PyPI","purl":"pkg:pypi/ansible"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.4"}]}],"versions":["2.8.0","2.8.1","2.8.2","2.8.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cqmr-rcpr-cxh3/GHSA-cqmr-rcpr-cxh3.json"}},{"package":{"name":"ansible","ecosystem":"PyPI","purl":"pkg:pypi/ansible"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.7.13"}]}],"versions":["2.7.0","2.7.1","2.7.10","2.7.11","2.7.12","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.7.8","2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cqmr-rcpr-cxh3/GHSA-cqmr-rcpr-cxh3.json"}},{"package":{"name":"ansible","ecosystem":"PyPI","purl":"pkg:pypi/ansible"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.19"}]}],"versions":["2.6.0","2.6.1","2.6.10","2.6.11","2.6.12","2.6.13","2.6.14","2.6.15","2.6.16","2.6.17","2.6.18","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","2.6.7","2.6.8","2.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cqmr-rcpr-cxh3/GHSA-cqmr-rcpr-cxh3.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10206"},{"type":"WEB","url":"https://github.com/ansible/ansible/commit/4b5aed4e5af4c7aab621662f50a289e99b8ac393"},{"type":"WEB","url":"https://github.com/ansible/ansible/commit/d39488ece44956f6a169a498b067bbef54552be1"},{"type":"WEB","url":"https://github.com/ansible/ansible/commit/d728127310b4f3a40ce8b9df3affb88ffaeea073"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10206"},{"type":"PACKAGE","url":"https://github.com/ansible/ansible"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-145.yaml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html"},{"type":"WEB","url":"https://www.debian.org/security/2021/dsa-4950"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html"}],"database_specific":{"cwe_ids":["CWE-20","CWE-522"],"github_reviewed":true,"github_reviewed_at":"2022-10-07T21:53:13Z","nvd_published_at":"2019-11-22T13:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}