CVE-2021-20180: Medium severity red hat ansible vulnerability
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucketpipelinevariable module. This flaw allows an attacker to steal bitbucketpipeline credentials. The highest threat from this vulnerability is to confidentiality.
Other sources
The bitbucketpipeline module leaks sensitive info such as secret values. This could lead in disclosing those credentials for every user which has access to the output of playbook execution.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in ansible module?
The vulnerability ID for this flaw in ansible module is CVE-2021-20180.
What is the severity of CVE-2021-20180?
The severity of CVE-2021-20180 is medium.
How does this vulnerability in ansible module expose credentials?
This vulnerability in ansible module exposes credentials in the console log by default.
What version of ansible is affected by this vulnerability?
Versions up to and including 2.9.18 of ansible are affected by this vulnerability.
Are there any fixes available for this vulnerability in ansible module?
Yes, applying version 2.9.18 of ansible will fix this vulnerability.