Description
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3695-1 | ansible security update |
Github GHSA |
GHSA-8f4m-hccc-8qph | Insertion of Sensitive Information into Log File in ansible |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Oracle
Subscribe
Virtualization
Subscribe
Redhat
Subscribe
Ansible
Subscribe
Ansible Automation Platform
Subscribe
Ansible Engine
Subscribe
Ansible Tower
Subscribe
Cisco Nx-os Collection
Subscribe
Community General Collection
Subscribe
Community Network Collection
Subscribe
Docker Community Collection
Subscribe
Google Cloud Platform Ansible Collection
Subscribe
Rhev Hypervisor
Subscribe
Rhev Manager
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:30:07.571Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20191
No data.
Status : Modified
Published: 2021-05-26T21:15:08.193
Modified: 2024-11-21T05:46:06.130
Link: CVE-2021-20191
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA