CVE-2021-20228 is a confidentiality flaw in Ansible Engine versions up to 2.9.18, affecting various Ansible Automation Platform and Debian Linux products. This vulnerability allows sensitive information to be exposed due to improper masking and a bypass of the no_log feature within the basic.py module's sub-option. Rated 7.5 HIGH on CVSS, it presents a network-exploitable, low-complexity threat with high confidentiality impact. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9.18CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_engine:2.9.18:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_engine:2.0:*:*:*:*:*:*:* | ||
2.9CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_engine:2.9:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Ansible Exposes Sensitive Information
May 25, 2022A flaw was found in the Ansible Engine 2.9.18 where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
Apr 13, 2021ansible: basic.py no_log with fallback option
Jan 29, 2021