CVE-2021-3620
medium
CVSS v3
—
CVSS v2
—
VIR risk
5.5
Description
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3620.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3620
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | affected | | |
| debian | forky | fixed | 5.4.0-1 |
| debian | sid | fixed | 5.4.0-1 |
| debian | bookworm | fixed | 5.4.0-1 |
| debian | bullseye | fixed | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 |
| debian | trixie | fixed | 5.4.0-1 |
| sles | affected | |
References
- https://security-tracker.debian.org/tracker/CVE-2021-3620
- https://nvd.nist.gov/vuln/detail/CVE-2021-3620
- https://github.com/ansible/ansible/commit/fe28767970c8ec62aabe493c46b53a5de1e5fac0
- https://access.redhat.com/errata/RHSA-2021:3871
- https://access.redhat.com/errata/RHSA-2021:3872
- https://access.redhat.com/errata/RHSA-2021:3874
- https://access.redhat.com/errata/RHSA-2021:4703
- https://access.redhat.com/errata/RHSA-2021:4750
- https://access.redhat.com/security/cve/CVE-2021-3620
- https://bugzilla.redhat.com/show_bug.cgi?id=1975767
- https://github.com/advisories/GHSA-4r65-35qq-ch8j
- https://github.com/ansible/ansible
- https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#security-fixes
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2022-164.yaml
- https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html
- https://www.suse.com/security/cve/CVE-2021-3620.html
Verify integrity in audit chain (admin only). AS-IS.