CVE Database
/

CVE-2021-20191

Back to search

CVE-2021-20191

Published: May 26, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.

VendorProductVersions

n/a

ansible

affected
ansible 2.9.18

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now