ZeroHour

CVE-2021-20191

CVSS 3.1
5.5 medium
EPSS
<1%p28
Published
()
Modified
Description

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

Vendors
oracleredhat
Products
virtualization, ansible, ansible tower, cisco nx-os collection, community general collection, community network collection, docker community collection, google cloud platform ansible collection
Weakness
CWE-532
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.