CVE-2021-20228: Infoleak
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the nolog feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
Other sources
A flaw was found in the Ansible Engine prior to 2.10.6rc1, 2.9.18rc1, and 2.8.19rc1, where sensitive info is not masked by default and is not protected by the nolog feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
— GitHub
A flaw was found in the Ansible Engine, where sensitive info is not masked by default and is not protected by the nolog feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
The return value of a specific module i.e. basic.py of ansible engine is not being masked by default while using the fallback sub-option.The return value may contain sensitive info like secret Or Credentials.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-20228?
CVE-2021-20228 is a vulnerability in Ansible Engine where sensitive information is not masked by default and can be obtained by an attacker.
How severe is CVE-2021-20228?
CVE-2021-20228 has a severity rating of 7.5 (high).
What software is affected by CVE-2021-20228?
Ansible Engine versions from 2.8.0 to 2.8.19, 2.9.0 to 2.9.18, and 2.10.0 to 2.10.7 are affected. Redhat Ansible Engine 2.9.18 and Ansible versions 0:2.9.18-1.el7ae and 0:2.9.18-1.el8ae are also affected.
How can I fix CVE-2021-20228?
To fix CVE-2021-20228, update your Ansible Engine to version 2.8.19, 2.9.18, or 2.10.7.
Where can I find more information about CVE-2021-20228?
You can find more information about CVE-2021-20228 on the NIST National Vulnerability Database (NVD) website and the relevant GitHub pull requests (PR #73487 and PR #73492).