Vulnerability Name:

CVE-2021-20228 (CCN-201040)

Assigned:2020-12-17
Published:2021-04-06
Updated:2022-08-05
Summary:A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-20228

Source: CCN
Type: Red Hat Bugzilla - Bug 1925002
(CVE-2021-20228) - CVE-2021-20228 ansible: basic.py no_log with fallback option

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1925002

Source: XF
Type: UNKNOWN
ansible-cve202120228-info-disc(201040)

Source: CCN
Type: ansible GIT Repository
no_log mask suboption fallback values and defaults CVE-2021-20228 #73487

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/ansible/ansible/pull/73487

Source: DEBIAN
Type: Third Party Advisory
DSA-4950

Source: CCN
Type: IBM Security Bulletin 6455627 (Elastic Storage System)
Ansible vulnerability affects IBM Elastic Storage System (CVE-2021-20228)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-20228

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:ansible_engine:2.9.18:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:redhat:ansible_engine:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:ansible_tower:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:ansible_engine:2.9:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:redhat:ansible_engine:2.9.18:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:elastic_storage_system:6.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:elastic_storage_system:6.0.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:744
    P
    Important security update for SUSE Manager Client Tools (Important)
    2022-09-08
    oval:org.opensuse.security:def:111931
    P
    ansible-2.9.24-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105499
    P
    ansible-2.9.24-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:84168
    P
    Security update for ansible (Moderate)
    2021-06-22
    oval:org.opensuse.security:def:84627
    P
    Security update for ansible (Moderate)
    2021-06-22
    oval:org.opensuse.security:def:39982
    P
    Security update for ansible (Moderate)
    2021-06-04
    oval:org.opensuse.security:def:44412
    P
    Security update for ansible (Moderate)
    2021-06-04
    BACK
    redhat ansible engine 2.9.18
    redhat ansible engine 2.0
    redhat ansible tower 3.0
    redhat ansible engine 2.9
    redhat ansible automation platform 1.2
    debian debian linux 10.0
    redhat ansible engine 2.9.18
    ibm elastic storage system 6.0.0
    ibm elastic storage system 6.0.2.0