First published: Wed Jan 13 2021(Updated: )
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible | <0:2.9.18-1.el7ae | 0:2.9.18-1.el7ae |
redhat/ansible | <0:2.9.18-1.el8ae | 0:2.9.18-1.el8ae |
Redhat Ansible | <2.9.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this flaw in ansible module is CVE-2021-20180.
The severity of CVE-2021-20180 is medium.
This vulnerability in ansible module exposes credentials in the console log by default.
Versions up to and including 2.9.18 of ansible are affected by this vulnerability.
Yes, applying version 2.9.18 of ansible will fix this vulnerability.