ZeroHour

CVE-2021-3620

CVSS 3.1
5.5 medium
EPSS
<1%p32
Published
()
Modified
Description

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

Vendors
redhat
Products
ansible automation platform early access, ansible engine, openstack, virtualization, virtualization for ibm power little endian, virtualization host, virtualization manager, enterprise linux, enterprise linux for power little endian
Weakness
CWE-209
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.