ansible: multiple modules expose secured values
Published May 26, 2021
5.5
MEDIUMCVSS 3.1
EPSS 0.35%
Description
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
Affected products
- Vendor n/a Product Ansible Defaultn/a
- Version ansible 2.9.18StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible | n/a |
|
- 4.0
- < 2.8.19
- ≥ 2.9.0 · < 2.9.18
- ≥ 2.10.0 · < 2.10.7
- 3.0
- < 1.4.0
- < 1.3.6
- ≥ 2.0.0 · < 2.0.1
- < 1.3.2
- ≥ 2.0.0 · < 2.0.1
- < 1.2.2
- 1.0.2
No data.
Red Hat Ansible Automation Platform 1.2 for RHEL 7
ansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1
Fixed · RHSA-2021:1079
Red Hat Ansible Automation Platform 1.2 for RHEL 7
ansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12
Fixed · RHSA-2021:1079
Red Hat Ansible Automation Platform 1.2 for RHEL 7
ansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15
Fixed · RHSA-2021:1079
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.9.18-1.el7ae
Fixed · RHSA-2021:0663
Red Hat Ansible Engine 2 for RHEL 8
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:0663
Red Hat Ansible Engine 2.9 for RHEL 7
ansible-0:2.9.18-1.el7ae
Fixed · RHSA-2021:0664
Red Hat Ansible Engine 2.9 for RHEL 8
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:0664
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:2180
Red Hat Virtualization Engine 4.4
ansible-0:2.9.18-1.el8ae
Fixed · RHSA-2021:2180
Red Hat Ansible Tower 3
ansible
Out of support scope
Red Hat Storage 3
ansible
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | ansible-automation-platform/platform-resource-operator-bundle:v0.1.1-1 | Fixed | RHSA-2021:1079 |
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | ansible-automation-platform/platform-resource-rhel7-operator:v0.1.0-12 | Fixed | RHSA-2021:1079 |
| Red Hat Ansible Automation Platform 1.2 for RHEL 7 | ansible-automation-platform/platform-resource-runner-rhel7:v0.1.0-15 | Fixed | RHSA-2021:1079 |
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.9.18-1.el7ae | Fixed | RHSA-2021:0663 |
| Red Hat Ansible Engine 2 for RHEL 8 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:0663 |
| Red Hat Ansible Engine 2.9 for RHEL 7 | ansible-0:2.9.18-1.el7ae | Fixed | RHSA-2021:0664 |
| Red Hat Ansible Engine 2.9 for RHEL 8 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:0664 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:2180 |
| Red Hat Virtualization Engine 4.4 | ansible-0:2.9.18-1.el8ae | Fixed | RHSA-2021:2180 |
| Red Hat Ansible Tower 3 | ansible | Out of support scope | n/a |
| Red Hat Storage 3 | ansible | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The version of ansible shipped with Red Hat Gluster Storage (RHGS) 3 includes the vulnerable `network/nxos/nxos_*` modules. However, RHGS 3 no longer maintains its own version of Ansible, prerequisite is to enable ansible repository in order to consume the latest version of ansible which has many bug and security fixes.
References (12)
- https://access.redhat.com/security/cve/CVE-2021-20191 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2021-20191
- https://bugzilla.redhat.com/show_bug.cgi?id=1916813 Issue TrackingVendor Advisory
- https://github.com/advisories/GHSA-8f4m-hccc-8qph Advisory
- https://github.com/ansible/ansible/commit/cc82d986c40328d4ae81298a9d287c95a6326bb0
- https://github.com/ansible/ansible/commit/d74a1b1d1325af2a24848044cf2858987f5a3ecc
- https://github.com/ansible/ansible/pull/73488
- https://github.com/ansible/ansible/pull/73489
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2021-124.yaml
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2021-20191
- https://www.cve.org/CVERecord?id=CVE-2021-20191
Change history (0)
No recorded changes yet.