CVE-2021-20191

EUVD-2021-0008
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
oraclevirtualization
4.0
redhatansible
𝑥
< 2.8.19
redhatansible
2.9.0 ≤
𝑥
< 2.9.18
redhatansible
2.10.0 ≤
𝑥
< 2.10.7
redhatansible_tower
3.0
redhatcisco_nx-os_collection
𝑥
< 1.4.0
redhatcommunity_general_collection
𝑥
< 1.3.6
redhatcommunity_general_collection
2.0.0 ≤
𝑥
< 2.0.1
redhatcommunity_network_collection
𝑥
< 1.3.2
redhatcommunity_network_collection
2.0.0 ≤
𝑥
< 2.0.1
redhatdocker_community_collection
𝑥
< 1.2.2
redhatgoogle_cloud_platform_ansible_collection
1.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ansible
bookworm
7.7.0+dfsg-3+deb12u1
fixed
bullseye
2.10.7+merged+base+2.10.17+dfsg-0+deb11u1
fixed
sid
10.5.0+dfsg-2
fixed
trixie
10.5.0+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ansible
bionic
needs-triage
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
needs-triage
xenial
needs-triage