
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw was discovered in Ansible Engine 2.9.18 (CVE-2021-20228) where sensitive information is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module (CVE Mitre, NVD).
The vulnerability exists in the basic.py module of Ansible Engine where the return value is not being masked by default while using the fallback sub-option. This affects the no_log feature's functionality, which is designed to protect sensitive information. The issue specifically relates to how default and fallback values for no_log fields are handled in the module output (Red Hat Bugzilla, GitHub PR).
This vulnerability allows an attacker to obtain sensitive information such as secrets or credentials that should have been masked. The highest threat from this vulnerability is to confidentiality (CVE Mitre).
The vulnerability affects the default configuration of Ansible Engine 2.9.18 and requires access to the Ansible output to view the exposed sensitive information (Red Hat Bugzilla).
The issue has been addressed in multiple products including Red Hat Ansible Engine 2 for RHEL 7 and 8, Red Hat Ansible Engine 2.9 for RHEL 7 and 8, and Red Hat Ansible Automation Platform 1.2. Updates are available through various security advisories including RHSA-2021:0663, RHSA-2021:0664, and RHSA-2021:1079 (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."