module: bitbucket_pipeline_variable exposes secured values
Published Mar 16, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.31%
Description
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
Affected products
- Vendor n/a Product Ansible Defaultunknown
Affected
- Fixed in ansible 2.9.18
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Ansible | unknown | Affected
|
No data.
Red Hat Ansible Automation Platform 1.2 for RHEL 7
ansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1
Fixed · RHSA-2021:1079
Red Hat Ansible Automation Platform 1.2 for RHEL 7
ansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12
Fixed · RHSA-2021:1079
Red Hat Ansible Automation Platform 1.2 for RHEL 7
ansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15
Fixed · RHSA-2021:1079
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.18-1.el7ae
Fixed · RHSA-2021:0663
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:0663
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.18-1.el7ae
Fixed · RHSA-2021:0664
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:0664
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:2180
Red Hat Virtualization Engine 4.4
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:2180
Red Hat Ansible Tower 3
ansible
Out of support scope
Red Hat Storage 3
ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | ansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1 | Fixed | RHSA-2021:1079 |
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | ansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12 | Fixed | RHSA-2021:1079 |
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | ansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15 | Fixed | RHSA-2021:1079 |
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.18-1.el7ae | Fixed | RHSA-2021:0663 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:0663 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.18-1.el7ae | Fixed | RHSA-2021:0664 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:0664 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:2180 |
| Red Hat Virtualization Engine 4.4 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:2180 |
| Red Hat Ansible Tower 3 | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The version of Ansible provided in Red Hat Gluster Storage 3 does not contain the vulnerable bitbucket module and is not affected by this vulnerability. However, Red Hat Gluster Storage 3 no longer maintains its own version of Ansible. The prerequisite is to enable the Ansible repository in order to consume the latest version of Ansible, which includes bug and security fixes.
References (12)
- https://access.redhat.com/security/cve/CVE-2021-20180 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1915808 x_refsource_MISCIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1413 Advisory
- https://github.com/advisories/GHSA-fh5v-5f35-2rv2 Advisory
- https://github.com/ansible/ansible/blob/v2.8.19/changelogs/CHANGELOG-v2.8.rst
- https://github.com/ansible/ansible/blob/v2.9.18/changelogs/CHANGELOG-v2.9.rst
- https://github.com/ansible/ansible/pull/73242
- https://github.com/ansible/ansible/pull/73243
- https://github.com/ansible/ansible/tree/v2.7.18/lib/ansible/modules/source_control
- https://github.com/ansible/ansible/tree/v2.8.0a1/lib/ansible/modules/source_control
- https://nvd.nist.gov/vuln/detail/CVE-2021-20180
- https://www.cve.org/CVERecord?id=CVE-2021-20180
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub