A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Oracle
Subscribe
|
Virtualization
Subscribe
|
|
Redhat
Subscribe
|
Ansible
Subscribe
Ansible Automation Platform
Subscribe
Ansible Engine
Subscribe
Ansible Tower
Subscribe
Cisco Nx-os Collection
Subscribe
Community General Collection
Subscribe
Community Network Collection
Subscribe
Docker Community Collection
Subscribe
Google Cloud Platform Ansible Collection
Subscribe
Rhev Hypervisor
Subscribe
Rhev Manager
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3695-1 | ansible security update |
Github GHSA |
GHSA-8f4m-hccc-8qph | Insertion of Sensitive Information into Log File in ansible |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:30:07.571Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20191
No data.
Status : Modified
Published: 2021-05-26T21:15:08.193
Modified: 2024-11-21T05:46:06.130
Link: CVE-2021-20191
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA