CVE-2021-20191 describes a flaw in Ansible versions prior to 2.9.18, affecting products like Oracle and Red Hat, where sensitive credentials are inadvertently exposed in console logs. This vulnerability, categorized as a medium severity issue with a CVSS score of 5.5, allows an attacker with local access to compromise data confidentiality by stealing these disclosed credentials. There is currently no evidence of active exploitation, nor is public exploit code available, and the vulnerability has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:oracle:virtualization:4.0:*:*:*:*:*:*:* | ||
< 2.8.19CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.18CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.10.0, < 2.10.7CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Insertion of Sensitive Information into Log File in ansible
Jun 1, 2021A flaw was found in ansible. Credentials such as secrets are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
May 11, 2021ansible: multiple modules expose secured values
Jan 15, 2021