VDB

PYSEC-2019-2

PYSEC-2019-2 PUBLISHED CVSS 8.699999809265137 HIGH

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
PyPIansible1.6, 0, 2.7.0

Timeline

  • Jul 30, 2019 CVE Published
  • Nov 8, 2023 CVE Updated
  • May 18, 2026 Distribution Patch
  • May 18, 2026 Distribution Patch
  • May 18, 2026 Security Advisory
  • May 18, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›