Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-20191

Опубликовано: 26 мая 2021
Источник: debian
EPSS Низкий

Описание

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.10.7-1package
ansibleend-of-lifestretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1916813

  • https://github.com/ansible-collections/cisco.nxos/pull/227

  • https://github.com/ansible-collections/cisco.nxos/commit/120956963f47502151a358e4a7bc2a87f71813aa

EPSS

Процентиль: 11%
0.00037
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

CVSS3: 5
redhat
около 5 лет назад

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

CVSS3: 5.5
nvd
больше 4 лет назад

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

CVSS3: 5.5
msrc
больше 4 лет назад

A flaw was found in ansible. Credentials such as secrets are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

CVSS3: 5.5
github
больше 4 лет назад

Insertion of Sensitive Information into Log File in ansible

EPSS

Процентиль: 11%
0.00037
Низкий