Lucene search

K
osvGoogleOSV:GHSA-8F4M-HCCC-8QPH
HistoryJun 01, 2021 - 9:38 p.m.

Insertion of Sensitive Information into Log File in ansible

2021-06-0121:38:33
Google
osv.dev
7

0.0004 Low

EPSS

Percentile

15.6%

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.