Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3620
HistoryMar 03, 2022 - 6:23 p.m.

CVE-2021-3620

2022-03-0318:23:38
CWE-209
redhat
www.cve.org
5
ansible
engine
connection
module
sensitive information
credentials
error message
vulnerability
confidentiality

AI Score

5.7

Confidence

High

EPSS

0

Percentile

15.5%

A flaw was found in Ansible Engine’s ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CNA Affected

[
  {
    "product": "ansible",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in Ansible Engine v2.9.27"
      }
    ]
  }
]