A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | ansible | 2021-03-18 01:13 | ALAS2-2021-1613 |
Amazon Linux 2 - Ansible2 Extra | ansible | 2023-08-21 21:01 | ALAS2ANSIBLE2-2023-004 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
NVD | CVSSv2 | 2.1 | AV:L/AC:L/Au:N/C:P/I:N/A:N |
NVD | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |