Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3620

Опубликовано: 25 июн. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

Отчет

Red Hat Gluster Storage 3 no longer maintains its own version of Ansible. The prerequisite is to enable the Ansible repository in order to consume the latest version of Ansible, which has many bug and security fixes. Red Hat Ceph Storage 2 only provides fixes for bugs on an as-requested basis by a customer, and will not be fixed after discussion with engineering about the viability of a fix. Red Hat Ceph Storage 3 does not directly ship ansible, and thus is closed as won't fix. Red Hat Virtualization ships an affected version of ansible, however, the usage of ansible on the redhat-virtualization-host is only supported for self-hosted-engine installation and disaster recovery, where it is run locally. As such Impact is rated Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2AnsibleAffected
Red Hat Ceph Storage 2ansibleAffected
Red Hat Ceph Storage 3ansibleAffected
Red Hat Storage 3ansibleWill not fix
Red Hat Ansible Automation Platform 2.0 for RHEL 8ansibleFixedRHSA-2021:387414.10.2021
Red Hat Ansible Automation Platform 2.0 for RHEL 8ansible-coreFixedRHSA-2021:387414.10.2021
Red Hat Ansible Engine 2.9 for RHEL 7ansibleFixedRHSA-2021:387114.10.2021
Red Hat Ansible Engine 2.9 for RHEL 8ansibleFixedRHSA-2021:387114.10.2021
Red Hat Ansible Engine 2 for RHEL 7ansibleFixedRHSA-2021:387214.10.2021
Red Hat Ansible Engine 2 for RHEL 8ansibleFixedRHSA-2021:387214.10.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1975767Ansible: ansible-connection module discloses sensitive info in traceback error message

EPSS

Процентиль: 46%
0.00228
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
nvd
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 3 лет назад

A flaw was found in Ansible Engine's ansible-connection module, where ...

CVSS3: 5.5
github
больше 3 лет назад

Ansible discloses sensitive information in traceback error message

EPSS

Процентиль: 46%
0.00228
Низкий

5.5 Medium

CVSS3