CVE Vulnerabilities

CVE-2021-20178

Insertion of Sensitive Information into Log File

Published: May 26, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
AnsibleRedhat*2.9.18 (excluding)
Ansible_towerRedhat3.0 (including)3.0 (including)
Red Hat Ansible Automation Platform 1.2 for RHEL 7RedHatansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1*
Red Hat Ansible Automation Platform 1.2 for RHEL 7RedHatansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12*
Red Hat Ansible Automation Platform 1.2 for RHEL 7RedHatansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15*
Red Hat Ansible Engine 2.9 for RHEL 7RedHatansible-0:2.9.18-1.el7ae*
Red Hat Ansible Engine 2.9 for RHEL 8RedHatansible-0:2.9.18-1.el8ae*
Red Hat Ansible Engine 2 for RHEL 7RedHatansible-0:2.9.18-1.el7ae*
Red Hat Ansible Engine 2 for RHEL 8RedHatansible-0:2.9.18-1.el8ae*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatansible-0:2.9.18-1.el8ae*
Red Hat Virtualization Engine 4.4RedHatansible-0:2.9.18-1.el8ae*
AnsibleUbuntubionic*
AnsibleUbuntufocal*
AnsibleUbuntugroovy*
AnsibleUbuntuhirsute*
AnsibleUbuntuimpish*
AnsibleUbuntukinetic*
AnsibleUbuntulunar*
AnsibleUbuntumantic*
AnsibleUbuntuoracular*
AnsibleUbuntuplucky*
AnsibleUbuntutrusty*
AnsibleUbuntutrusty/esm*
AnsibleUbuntuxenial*

Potential Mitigations

References