5.5
CVSSv3

CVE-2021-20191

Published: 26/05/2021 Updated: 28/12/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A flaw was found in ansible. The 'authkey' and 'privkey' credentials are disclosed by default and not protected by no_log feature when using the snmp_facts module. Attackers could take advantage of this information to steal the SNMP credentials. The highest threat from this vulnerability is to data confidentiality. (CVE-2021-20178) A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an malicious user to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality. (CVE-2021-20180) A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. (CVE-2021-20191)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle virtualization 4.0

redhat ansible tower 3.0

redhat google cloud platform ansible collection 1.0.2

redhat cisco nx-os collection

redhat ansible

redhat community general collection

redhat community network collection

redhat docker community collection

Vendor Advisories

Debian Bug report logs - #985753 CVE-2021-20178 CVE-2021-20180 CVE-2021-20191 Package: ansible; Maintainer for ansible is Harlan Lieberman-Berg <hlieberman@debianorg>; Source for ansible is src:ansible (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 22 Mar 2021 21:57:04 UTC Severit ...
A flaw was found in ansible The 'authkey' and 'privkey' credentials are disclosed by default and not protected by no_log feature when using the snmp_facts module Attackers could take advantage of this information to steal the SNMP credentials The highest threat from this vulnerability is to data confidentiality (CVE-2021-20178) A flaw was found ...
A flaw was found in ansible The 'authkey' and 'privkey' credentials are disclosed by default and not protected by no_log feature when using the snmp_facts module Attackers could take advantage of this information to steal the SNMP credentials The highest threat from this vulnerability is to data confidentiality (CVE-2021-20178) A flaw was found ...
A flaw was found in ansible-collection where credentials such as secrets are being disclosed in console log by default and not protected by no_log feature when using those modules An attacker can take advantage of this information to steal those credentials ...