CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
oraclevirtualization
4.0
redhatansible
𝑥
< 2.8.19
redhatansible
2.9.0 ≤
𝑥
< 2.9.18
redhatansible
2.10.0 ≤
𝑥
< 2.10.7
redhatansible_tower
3.0
redhatcisco_nx-os_collection
𝑥
< 1.4.0
redhatcommunity_general_collection
𝑥
< 1.3.6
redhatcommunity_general_collection
2.0.0 ≤
𝑥
< 2.0.1
redhatcommunity_network_collection
𝑥
< 1.3.2
redhatcommunity_network_collection
2.0.0 ≤
𝑥
< 2.0.1
redhatdocker_community_collection
𝑥
< 1.2.2
redhatgoogle_cloud_platform_ansible_collection
1.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ansible
bullseye
2.10.7+merged+base+2.10.17+dfsg-0+deb11u1
fixed
bookworm
7.7.0+dfsg-3+deb12u1
fixed
sid
10.5.0+dfsg-2
fixed
trixie
10.5.0+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ansible
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage