PT-2019-5284 · Red Hat+3 · Ansible+3

·

CVE-2019-14856

·

Publicado

2019-11-26

·

Atualizado

2026-06-03

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 2.8.6 Ansible versions prior to 2.7.14 Ansible versions prior to 2.6.20
Description The issue is related to insufficient input validation in the Ansible configuration management system. This could allow a remote attacker to gain unauthorized access to protected information. A data disclosure flaw was found in Ansible, where password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters, as they are not properly wrapped. The highest threat from this issue is to data confidentiality.
Recommendations For versions prior to 2.8.6, update to version 2.8.6 or later. For versions prior to 2.7.14, update to version 2.7.14 or later. For versions prior to 2.6.20, update to version 2.6.20 or later.

Correção

RCE

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1453
ALT-PU-2020-1490
BDU:2020-02200
CVE-2019-14856
GHSA-6FQ2-X65V-V9H7
OPENSUSE-SU-2020:0513-1
OPENSUSE-SU-2020:0523-1
OPENSUSE-SU-2020_0513-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
PYSEC-2019-146
RHSA-2019:3201
RHSA-2019:3202
RHSA-2019:3203
RHSA-2019:3207
RHSA-2020:0756
SUSE-SU-2020:3309-1

Produtos afetados

Alt Linux
Ansible
Ansible-Core
Suse