CVE-2021-3620: Medium severity redhat Ansible Automation Platform Early Access vulnerability
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Other sources
Ansible is an IT automation system that handles configuration management, application deployment, cloud provisioning, ad-hoc task execution, network automation, and multi-node orchestration. A flaw was found in Ansible Engine's ansible-connection module where sensitive information, such as the Ansible user credentials, is disclosed by default in the traceback error message when Ansible receives an unexpected response from setoptions. The highest threat from this vulnerability is confidentiality.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3620?
CVE-2021-3620 is a vulnerability in Ansible Engine's ansible-connection module where sensitive information such as Ansible user credentials is disclosed in the traceback error message.
What is the severity of CVE-2021-3620?
The severity of CVE-2021-3620 is high.
How does CVE-2021-3620 affect Redhat Ansible?
Redhat Ansible versions up to 2.9.27 and 2.11.6 are affected by CVE-2021-3620.
How can I fix CVE-2021-3620 in Redhat Ansible?
To fix CVE-2021-3620 in Redhat Ansible, upgrade to version 2.9.27-1.el8a or 2.11.6-1.el8a.
Where can I find more information about CVE-2021-3620?
You can find more information about CVE-2021-3620 in the references provided.