CVE-2019-10206: Debian Linux
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.
Affected products
- Debian Debian Linux: version 10.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.1 only
- Red Hat Ansible: from 2.6.0, before 2.6.19 (fixed in 2.6.19); from 2.7.0, before 2.7.13 (fixed in 2.7.13); from 2.8.0, before 2.8.4 (fixed in 2.8.4)
Published 2019-11-22. Last modified 2026-06-17.