CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2021-20228 — HIGH severity vulnerability | Release Alert
CVE-2021-20228
7.5
HIGHCVSS v3
Published
April 29, 2021
CVSS v2
5 MEDIUM
Affected
2 projects
Assigned by
Red Hat
Severity scale
010
Description
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
GitHubAnsible is a radically simple IT automation platform that makes your applications and systems easier to deploy and maintain. Automate everything from code deployment to network configuration to cloud management, in a language that approaches plain English, using SSH, with no agents to install on remote systems. https://docs.ansible.com.