Bug 1717311 (CVE-2019-10156) - CVE-2019-10156 ansible: unsafe template evaluation of returned module data can lead to information disclosure
Summary: CVE-2019-10156 ansible: unsafe template evaluation of returned module data ca...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-10156
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1717312 1717313 1717934 1717935 1718357 1718358 1719543 1719544 1719545 1722410 1722411
Blocks: 1717332
TreeView+ depends on / blocked
 
Reported: 2019-06-05 07:52 UTC by Marian Rehak
Modified: 2021-02-16 21:51 UTC (History)
54 users (show)

Fixed In Version: ansible-engine 2.6.18, ansible-engine 2.7.12, ansible-engine 2.8.2
Clone Of:
Environment:
Last Closed: 2019-07-12 13:07:15 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:1705 0 None None None 2019-07-09 08:44:08 UTC
Red Hat Product Errata RHSA-2019:1706 0 None None None 2019-07-09 08:49:26 UTC
Red Hat Product Errata RHSA-2019:1707 0 None None None 2019-07-09 09:45:01 UTC
Red Hat Product Errata RHSA-2019:1708 0 None None None 2019-07-09 09:44:39 UTC
Red Hat Product Errata RHSA-2019:3744 0 None None None 2019-11-06 15:26:38 UTC
Red Hat Product Errata RHSA-2019:3789 0 None None None 2019-11-07 13:46:19 UTC

Description Marian Rehak 2019-06-05 07:52:44 UTC
[ansible_password] in the ~/.ssh/authorized_keys file is repalced by administrator's password on remote node by templating.

Upstream pull:

https://github.com/ansible/ansible/pull/57188

Comment 1 Marian Rehak 2019-06-05 07:53:02 UTC
Created ansible tracking bugs for this issue:

Affects: epel-all [bug 1717312]
Affects: fedora-all [bug 1717313]

Comment 2 Marian Rehak 2019-06-05 08:45:21 UTC
Acknowledgments:

Name: Ichiko Sakamoto (Solution Innovators)

Comment 6 Dave Baker 2019-06-06 19:33:18 UTC
Updated title

Comment 14 Hardik Vyas 2019-06-20 09:54:57 UTC
Gluster uses Ansible package from Ansible repository hence marked as WONTFIX and it will consume fixes from core Ansible.
Refer:
	https://url.corp.redhat.com/prerequisites
	https://url.corp.redhat.com/gdeploy-support-install-ansible

For Ceph we still maintain Ansible atleast for Ubuntu which uses Ansible package from Ceph repository.
Refer:
	https://url.corp.redhat.com/ubuntu
	https://url.corp.redhat.com/enabling-the-red-hat-ceph-storage-repositories
	https://url.corp.redhat.com/upgrading-a-red-hat-ceph-storage-cluster

Comment 16 errata-xmlrpc 2019-07-09 08:44:06 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Engine 2.7 for RHEL 7

Via RHSA-2019:1705 https://access.redhat.com/errata/RHSA-2019:1705

Comment 17 errata-xmlrpc 2019-07-09 08:49:24 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Engine 2 for RHEL 8
  Red Hat Ansible Engine 2 for RHEL 7

Via RHSA-2019:1706 https://access.redhat.com/errata/RHSA-2019:1706

Comment 18 errata-xmlrpc 2019-07-09 09:44:37 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Engine 2.8 for RHEL 8
  Red Hat Ansible Engine 2.8 for RHEL 7

Via RHSA-2019:1708 https://access.redhat.com/errata/RHSA-2019:1708

Comment 19 errata-xmlrpc 2019-07-09 09:44:59 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Engine 2.6 for RHEL 7

Via RHSA-2019:1707 https://access.redhat.com/errata/RHSA-2019:1707

Comment 20 Product Security DevOps Team 2019-07-12 13:07:15 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-10156

Comment 21 errata-xmlrpc 2019-11-06 15:26:36 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 14.0 (Rocky)

Via RHSA-2019:3744 https://access.redhat.com/errata/RHSA-2019:3744

Comment 22 errata-xmlrpc 2019-11-07 13:46:17 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 13.0 (Queens)

Via RHSA-2019:3789 https://access.redhat.com/errata/RHSA-2019:3789


Note You need to log in before you can comment on or make changes to this bug.