SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-20191

Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules.

MEDIUM 5.5EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.35% probability · 28th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
oracle/virtualization · redhat/ansible · redhat/ansible tower · redhat/cisco nx-os collection · redhat/community general collection · redhat/community network collection · redhat/docker community collection · redhat/google cloud platform ansible collection
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.