[ASA-202102-9] ansible: information disclosure
rgacogne at archlinux.org
Fri Feb 12 07:04:19 UTC 2021
Arch Linux Security Advisory ASA-202102-9
Date : 2021-02-06
CVE-ID : CVE-2021-20178 CVE-2021-20180 CVE-2021-20191
Package : ansible
Type : information disclosure
Remote : No
Link : https://security.archlinux.org/AVG-1437
The package ansible before version 2.10.7-1 is vulnerable to
Upgrade to 2.10.7-1.
# pacman -Syu "ansible>=2.10.7-1"
The problems have been fixed upstream in version 2.10.7.
- CVE-2021-20178 (information disclosure)
A flaw was found in Ansible before version 2.10.6 where the 'authkey'
and 'privkey' credentials are disclosed by default and not protected by
no_log feature when using the snmp_facts module. Attackers could take
advantage of this information to steal the SNMP credentials.
- CVE-2021-20180 (information disclosure)
A flaw was found in Ansible before version 2.10.6 where credentials
such as secrets are being disclosed in console log by default and not
protected by secured feature when using bitbucket_pipeline_variable
module. An attacker can take advantage of this information to steal
- CVE-2021-20191 (information disclosure)
A flaw was found in ansible-collection where credentials such as
secrets are being disclosed in console log by default and not protected
by no_log feature when using those modules. An attacker can take
advantage of this information to steal those credentials.
A local attacker can access sensitive information like credentials and
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 840 bytes
Desc: OpenPGP digital signature
More information about the arch-security