5.5

CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Virtualization Version 4.0
Redhat ≫ Ansible Version < 2.8.19
Redhat ≫ Ansible Version >= 2.9.0 < 2.9.18
Redhat ≫ Ansible Version >= 2.10.0 < 2.10.7
Redhat ≫ Ansible Tower Version 3.0
Redhat ≫ Cisco Nx-os Collection Version < 1.4.0
Redhat ≫ Community General Collection SwPlatform ansible Version < 1.3.6
Redhat ≫ Community General Collection SwPlatform ansible Version >= 2.0.0 < 2.0.1
Redhat ≫ Community Network Collection SwPlatform ansible Version < 1.3.2
Redhat ≫ Community Network Collection SwPlatform ansible Version >= 2.0.0 < 2.0.1
Redhat ≫ Docker Community Collection SwPlatform ansible Version < 1.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.276
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
https://bugzilla.redhat.com/show_bug.cgi?id=1916813
Vendor Advisory
Issue Tracking