CVE-2021-3620 is a medium-severity vulnerability in Ansible Engine's ansible-connection module that discloses sensitive Ansible user credentials within traceback error messages. This flaw primarily impacts confidentiality and affects various Red Hat products, including Ansible Automation Platform, Ansible Engine, and Red Hat Enterprise Linux. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and having a high impact on confidentiality. There is no user interaction required for exploitation. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_automation_platform_early_access:2.0:*:*:*:*:*:*:* | ||
< 2.9.27CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* | ||
1CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:1:*:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in Ansible Engine's ansible-connection module where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Mar 8, 2022Ansible discloses sensitive information in traceback error message
Mar 4, 2022Ansible: ansible-connection module discloses sensitive info in traceback error message
Jun 25, 2021