PT-2019-5284 · Red Hat+3 · Ansible+3
Pedro Sampaio
·
Published
2019-11-26
·
Updated
2025-11-21
·
CVE-2019-14856
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ansible versions prior to 2.8.6
Ansible versions prior to 2.7.14
Ansible versions prior to 2.6.20
Description
The issue is related to insufficient input validation in the Ansible configuration management system. This could allow a remote attacker to gain unauthorized access to protected information. A data disclosure flaw was found in Ansible, where password prompts in ansible-playbook and ansible-cli tools could expose passwords with special characters, as they are not properly wrapped. The highest threat from this issue is to data confidentiality.
Recommendations
For versions prior to 2.8.6, update to version 2.8.6 or later.
For versions prior to 2.7.14, update to version 2.7.14 or later.
For versions prior to 2.6.20, update to version 2.6.20 or later.
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ansible
Ansible-Core
Suse