CVE-2021-3681

Severity
5.5MEDIUM
EPSS
0.0%
top 86.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateApr 19

Description

A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5ansibleansible 3.3.0

🔴Vulnerability Details

2
GHSA
GHSA-wh68-r6p4-7cv3: A flaw was found in Ansible Galaxy Collections2022-04-19
CVEList
CVE-2021-3681: A flaw was found in Ansible Galaxy Collections2022-04-18

📋Vendor Advisories

1
Red Hat
ansible: Secrets leakage vulnerability with ansible collections and ansible galaxy2021-08-04
CVE-2021-3681 (MEDIUM CVSS 5.5) | A flaw was found in Ansible Galaxy | cvebase.io