5.5

CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleVirtualization Version4.0
RedhatAnsible Version < 2.8.19
RedhatAnsible Version >= 2.9.0 < 2.9.18
RedhatAnsible Version >= 2.10.0 < 2.10.7
RedhatAnsible Tower Version3.0
RedhatCisco Nx-os Collection Version < 1.4.0
RedhatCommunity General Collection SwPlatformansible Version < 1.3.6
RedhatCommunity General Collection SwPlatformansible Version >= 2.0.0 < 2.0.1
RedhatCommunity Network Collection SwPlatformansible Version < 1.3.2
RedhatCommunity Network Collection SwPlatformansible Version >= 2.0.0 < 2.0.1
RedhatDocker Community Collection SwPlatformansible Version < 1.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.