CVE-2021-3620

medium
Published 2022-03-04 · Modified 2026-02-22
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk
5.5

Description

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-3620.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-3620

OS impact

OSVersionStatusFixed in
arch archaffected
debian debianforkyfixed5.4.0-1
debian debiansidfixed5.4.0-1
debian debianbookwormfixed5.4.0-1
debian debianbullseyefixed2.10.7+merged+base+2.10.17+dfsg-0+deb11u1
debian debiantrixiefixed5.4.0-1
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIansible<2.9.272.9.27
python PyPIansible<fe28767970c8ec62aabe493c46b53a5de1e5fac0||<2.9.27fe28767970c8ec62aabe493c46b53a5de1e5fac0

References

Verify integrity in audit chain (admin only). AS-IS.