CVE Vulnerabilities

CVE-2021-20191

Insertion of Sensitive Information into Log File

Published: May 26, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
VirtualizationOracle4.0 (including)4.0 (including)
AnsibleRedhat*2.8.19 (excluding)
AnsibleRedhat2.9.0 (including)2.9.18 (excluding)
AnsibleRedhat2.10.0 (including)2.10.7 (excluding)
Ansible_towerRedhat3.0 (including)3.0 (including)
Cisco_nx-os_collectionRedhat*1.4.0 (excluding)
Community_general_collectionRedhat*1.3.6 (excluding)
Community_general_collectionRedhat2.0.0 (including)2.0.1 (excluding)
Community_network_collectionRedhat*1.3.2 (excluding)
Community_network_collectionRedhat2.0.0 (including)2.0.1 (excluding)
Docker_community_collectionRedhat*1.2.2 (excluding)
Google_cloud_platform_ansible_collectionRedhat1.0.2 (including)1.0.2 (including)
Red Hat Ansible Automation Platform 1.2 for RHEL 7RedHatansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1*
Red Hat Ansible Automation Platform 1.2 for RHEL 7RedHatansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12*
Red Hat Ansible Automation Platform 1.2 for RHEL 7RedHatansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15*
Red Hat Ansible Engine 2.9 for RHEL 7RedHatansible-0:2.9.18-1.el7ae*
Red Hat Ansible Engine 2.9 for RHEL 8RedHatansible-0:2.9.18-1.el8ae*
Red Hat Ansible Engine 2 for RHEL 7RedHatansible-0:2.9.18-1.el7ae*
Red Hat Ansible Engine 2 for RHEL 8RedHatansible-0:2.9.18-1.el8ae*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatansible-0:2.9.18-1.el8ae*
Red Hat Virtualization Engine 4.4RedHatansible-0:2.9.18-1.el8ae*
AnsibleUbuntubionic*
AnsibleUbuntufocal*
AnsibleUbuntugroovy*
AnsibleUbuntuhirsute*
AnsibleUbuntuimpish*
AnsibleUbuntukinetic*
AnsibleUbuntulunar*
AnsibleUbuntumantic*
AnsibleUbuntuoracular*
AnsibleUbuntuplucky*
AnsibleUbuntutrusty*
AnsibleUbuntutrusty/esm*
AnsibleUbuntuxenial*

Potential Mitigations

References