A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
The product writes sensitive information to a log file.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Ansible | Redhat | * | 2.9.18 (excluding) | 
| Ansible_tower | Redhat | 3.0 (including) | 3.0 (including) | 
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | RedHat | ansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1 | * | 
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | RedHat | ansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12 | * | 
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | RedHat | ansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15 | * | 
| Red Hat Ansible Engine 2.9 for RHEL 7 | RedHat | ansible-0:2.9.18-1.el7ae | * | 
| Red Hat Ansible Engine 2.9 for RHEL 8 | RedHat | ansible-0:2.9.18-1.el8ae | * | 
| Red Hat Ansible Engine 2 for RHEL 7 | RedHat | ansible-0:2.9.18-1.el7ae | * | 
| Red Hat Ansible Engine 2 for RHEL 8 | RedHat | ansible-0:2.9.18-1.el8ae | * | 
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | RedHat | ansible-0:2.9.18-1.el8ae | * | 
| Red Hat Virtualization Engine 4.4 | RedHat | ansible-0:2.9.18-1.el8ae | * | 
| Ansible | Ubuntu | bionic | * | 
| Ansible | Ubuntu | focal | * | 
| Ansible | Ubuntu | groovy | * | 
| Ansible | Ubuntu | hirsute | * | 
| Ansible | Ubuntu | impish | * | 
| Ansible | Ubuntu | kinetic | * | 
| Ansible | Ubuntu | lunar | * | 
| Ansible | Ubuntu | mantic | * | 
| Ansible | Ubuntu | oracular | * | 
| Ansible | Ubuntu | trusty | * | 
| Ansible | Ubuntu | trusty/esm | * | 
| Ansible | Ubuntu | xenial | * |