GHSA-8f4m-hccc-8qph
Dashboard / Vulnerabilities / GHSA-8f4m-hccc-8qph
GHSA-8f4m-hccc-8qph
Summary: Insertion of Sensitive Information into Log File in ansible
Details: A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-20191, https://github.com/ansible/ansible/pull/73488, https://github.com/ansible/ansible/pull/73489, https://github.com/ansible/ansible/commit/cc82d986c40328d4ae81298a9d287c95a6326bb0, https://github.com/ansible/ansible/commit/d74a1b1d1325af2a24848044cf2858987f5a3ecc, https://access.redhat.com/security/cve/cve-2021-20191, https://bugzilla.redhat.com/show_bug.cgi?id=1916813, https://github.com/advisories/GHSA-8f4m-hccc-8qph, https://github.com/ansible/ansible, https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2021-124.yaml, https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
Affected packages
Package
Name: ansible
Purl: pkg:pypi/ansible
Affected ranges
Type: ECOSYSTEM
Events:
