Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-20191


A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.


Published

2021-05-26T21:15:08.193

Last Modified

2024-11-21T05:46:06.130

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle virtualization 4.0 Yes
Application redhat ansible < 2.8.19 Yes
Application redhat ansible < 2.9.18 Yes
Application redhat ansible < 2.10.7 Yes
Application redhat ansible_tower 3.0 Yes
Application redhat cisco_nx-os_collection < 1.4.0 Yes
Application redhat community_general_collection < 1.3.6 Yes
Application redhat community_general_collection < 2.0.1 Yes
Application redhat community_network_collection < 1.3.2 Yes
Application redhat community_network_collection < 2.0.1 Yes
Application redhat docker_community_collection < 1.2.2 Yes
Application redhat google_cloud_platform_ansible_collection 1.0.2 Yes

References