ALPINE-CVE-2019-10156 PUBLISHED CVSS 5.400000095367432 MEDIUM

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

Risk Scores

CVSS v3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Alpine:v3.12ansible0, 0.3.1-r0, 0.4-r0
Alpine:v3.11ansible0, 0.3.1-r0, 0.4-r0
Alpine:v3.10ansible1.6.7-r0, 0, 0.3.1-r0
Alpine:v3.8ansible0, 0.3.1-r0, 0.4-r0
Alpine:v3.13ansible-base0, 0.3.1-r0, 0.4-r0
Alpine:v3.14ansible-base0, 0.3.1-r0, 0.4-r0

Timeline

References

Open in Interactive Console →