A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3695-1 | ansible security update |
![]() |
GHSA-8f4m-hccc-8qph | Insertion of Sensitive Information into Log File in ansible |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:30:07.571Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20191

No data.

Status : Modified
Published: 2021-05-26T21:15:08.193
Modified: 2024-11-21T05:46:06.130
Link: CVE-2021-20191


No data.