CVE-2019-10156: Debian Linux
Medium severity, CVSS 5.4. EPSS: 1.8% chance of exploitation in the next 30 days.
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Red Hat Ansible: before 2.6.18 (fixed in 2.6.18); from 2.7.0, before 2.7.12 (fixed in 2.7.12); from 2.8.0, before 2.8.2 (fixed in 2.8.2)
- Red Hat Openstack: version 13 only; version 14 only
Published 2019-07-30. Last modified 2026-06-17.