MEDIUM · 5.5

CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of...

Vulnerability Description

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OracleVirtualization4.0
RedhatAnsible< 2.8.19
RedhatAnsible Tower3.0
RedhatCisco Nx-Os Collection< 1.4.0
RedhatCommunity General Collection< 1.3.6
RedhatCommunity Network Collection< 1.3.2
RedhatDocker Community Collection< 1.2.2
RedhatGoogle Cloud Platform Ansible Collection1.0.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-20191?

CVE-2021-20191 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of...

How severe is CVE-2021-20191?

CVE-2021-20191 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-20191?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Virtualization, Redhat Ansible, Redhat Ansible Tower, Redhat Cisco Nx-Os Collection, Redhat Community General Collection.