CVE-2021-3620Information Exposure via Error Message in Redhat Ansible Engine

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 47.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateJun 7

Description

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

NVDredhat/ansible_engine< 2.9.27
PyPIredhat/ansible< 2.9.27
Debianredhat/ansible< 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1+3
CVEListV5redhat/ansibleFixed in Ansible Engine v2.9.27
CVEListV5redhat/ansible_automation_platform_early_accessFixed in Ansible Engine v2.9.27

Also affects: Enterprise Linux 8.0

Patches

🔴Vulnerability Details

4
OSV
Ansible discloses sensitive information in traceback error message2022-03-04
GHSA
Ansible discloses sensitive information in traceback error message2022-03-04
OSV
CVE-2021-3620: A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by defau2022-03-03
CVEList
CVE-2021-3620: A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by defau2022-03-03

📋Vendor Advisories

4
Ubuntu
Ansible vulnerabilities2022-06-07
Microsoft
A flaw was found in Ansible Engine's ansible-connection module where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest thre2022-03-08
Red Hat
Ansible: ansible-connection module discloses sensitive info in traceback error message2021-06-25
Debian
CVE-2021-3620: ansible - A flaw was found in Ansible Engine's ansible-connection module, where sensitive ...2021