A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3695-1 | ansible security update |
Github GHSA |
GHSA-8f4m-hccc-8qph | Insertion of Sensitive Information into Log File in ansible |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:30:07.571Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20191
No data.
Status : Modified
Published: 2021-05-26T21:15:08.193
Modified: 2024-11-21T05:46:06.130
Link: CVE-2021-20191
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA