Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3620

Опубликовано: 03 мар. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansible-corefixed2.12.0-1package
ansiblefixed5.4.0-1package
ansiblefixed2.10.7+merged+base+2.10.17+dfsg-0+deb11u1bullseyepackage
ansibleend-of-lifestretchpackage
ansible-baseremovedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1975767

  • https://github.com/ansible/ansible/commit/79e9dae29212a88aa60122ca6bd608947399017f

  • ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid

EPSS

Процентиль: 46%
0.00228
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
redhat
около 4 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
nvd
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.5
github
больше 3 лет назад

Ansible discloses sensitive information in traceback error message

EPSS

Процентиль: 46%
0.00228
Низкий