A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ansible-docUpgrade ansible | Mar 22, 2021 | Mar 22, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 26, 2021 |
| Centos_linux | — | Upgrade python3-ovirt-engine-sdk4Upgrade rubygem-ovirt-engine-sdk4-debugsourceUpgrade rubygem-ovirt-engine-sdk4Upgrade ovirt-ansible-collectionUpgrade rubygem-ovirt-engine-sdk4-debuginfoUpgrade python-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4-doc | Jun 2, 2021 | May 26, 2021 |
| Debian | — | Upgrade ansible | Jan 3, 2024 | May 26, 2021 |
| Redhat_linux | — | Upgrade rubygem-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4-docUpgrade ovirt-ansible-collectionUpgrade rubygem-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4Upgrade python-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4 | Jun 2, 2021 | May 26, 2021 |
| Suse | — | Upgrade wireUpgrade dracut-saltbootUpgrade python3-hwdataUpgrade golang-github-prometheus-node_exporterUpgrade python2-hwdataUpgrade ansibleUpgrade golang-github-qubitproducts-exporter_exporterUpgrade prometheus-blackbox_exporterUpgrade ansible-docUpgrade ansible-testUpgrade spacecmd | Mar 18, 2022 | May 26, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub