Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20228

Опубликовано: 29 янв. 2021
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

A flaw was found in the Ansible Engine, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Tower 3ansibleOut of support scope
Red Hat Ansible Automation Platform 1.2 for RHEL 7ansible-automation-platform/platform-resource-operator-bundleFixedRHSA-2021:107909.04.2021
Red Hat Ansible Automation Platform 1.2 for RHEL 7ansible-automation-platform/platform-resource-rhel7-operatorFixedRHSA-2021:107909.04.2021
Red Hat Ansible Automation Platform 1.2 for RHEL 7ansible-automation-platform/platform-resource-runner-rhel7FixedRHSA-2021:107909.04.2021
Red Hat Ansible Engine 2.9 for RHEL 7ansibleFixedRHSA-2021:066424.02.2021
Red Hat Ansible Engine 2.9 for RHEL 8ansibleFixedRHSA-2021:066424.02.2021
Red Hat Ansible Engine 2 for RHEL 7ansibleFixedRHSA-2021:066324.02.2021
Red Hat Ansible Engine 2 for RHEL 8ansibleFixedRHSA-2021:066324.02.2021
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8ansibleFixedRHSA-2021:218001.06.2021
Red Hat Virtualization Engine 4.4ansibleFixedRHSA-2021:218001.06.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200->CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1925002ansible: basic.py no_log with fallback option

EPSS

Процентиль: 36%
0.00149
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
nvd
почти 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
msrc
больше 4 лет назад

A flaw was found in the Ansible Engine 2.9.18 where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
debian
почти 5 лет назад

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is ...

CVSS3: 7.5
github
больше 3 лет назад

Ansible Exposes Sensitive Information

EPSS

Процентиль: 36%
0.00149
Низкий

5 Medium

CVSS3