CVE Vulnerabilities

CVE-2019-14856

Improper Authentication

Published: Nov 26, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
AnsibleRedhat2.6.0 (including)2.6.20 (excluding)
AnsibleRedhat2.7.0 (including)2.7.14 (excluding)
AnsibleRedhat2.8.0 (including)2.8.6 (excluding)
Red Hat Ansible Engine 2.6 for RHEL 7RedHatansible-0:2.6.20-1.el7ae*
Red Hat Ansible Engine 2.7 for RHEL 7RedHatansible-0:2.7.14-1.el7ae*
Red Hat Ansible Engine 2.8 for RHEL 7RedHatansible-0:2.8.6-1.el7ae*
Red Hat Ansible Engine 2.8 for RHEL 8RedHatansible-0:2.8.6-1.el8ae*
Red Hat Ansible Engine 2 for RHEL 7RedHatansible-0:2.8.6-1.el7ae*
Red Hat Ansible Engine 2 for RHEL 8RedHatansible-0:2.8.6-1.el8ae*
Red Hat OpenStack Platform 13.0 (Queens)RedHatansible-0:2.6.20-1.el7ae*
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSRedHatansible-0:2.6.20-1.el7ae*
AnsibleUbuntutrusty*

Potential Mitigations

References