CVE-2021-3620
03.03.2022, 19:15
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | ansible_automation_platform_early_access | 2.0 |
| redhat | ansible_engine | 𝑥 < 2.9.27 |
| redhat | openstack | 16.1 |
| redhat | virtualization | 4.0 |
| redhat | virtualization_for_ibm_power_little_endian | 4.0 |
| redhat | virtualization_host | 4.0 |
| redhat | virtualization_manager | 4.4 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ansible |
| ||||||||||||||||||||||||
| ansible-base |
| ||||||||||||||||||||||||
| ansible-core |
|
Common Weakness Enumeration
References