Junglewise Threat Intelligence

CVE-2021-20228: PYSEC-2021-1 - A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when

CVE-2021-20228 · Severity: low · CVSS 3.1 · Published 2021-04-29

Technologies: ansible (PyPI). Vendors: PyPI.

Executive brief

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.

Affected products

  • PyPI ansible

Related threats