A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3695-1 | ansible security update |
![]() |
GHSA-4r65-35qq-ch8j | Ansible discloses sensitive information in traceback error message |
![]() |
USN-5315-1 | Ansible vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:28:25.255Z
Reserved: 2021-06-24T00:00:00.000Z
Link: CVE-2021-3620

Updated: 2024-08-03T17:01:07.670Z

Status : Modified
Published: 2022-03-03T19:15:08.237
Modified: 2024-11-21T06:22:00.013
Link: CVE-2021-3620


No data.