A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 29, 2021 |
| Centos_linux | — | Upgrade ovirt-ansible-collectionUpgrade rubygem-ovirt-engine-sdk4-docUpgrade rubygem-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4-debugsourceUpgrade python-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4Upgrade python3-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4 | Jun 2, 2021 | Apr 29, 2021 |
| Debian | — | Upgrade ansible | Aug 9, 2021 | Apr 29, 2021 |
| Redhat_linux | — | Upgrade rubygem-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4Upgrade rubygem-ovirt-engine-sdk4Upgrade rubygem-ovirt-engine-sdk4-docUpgrade python-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4-debuginfoUpgrade ovirt-ansible-collection | Jun 2, 2021 | Apr 29, 2021 |
| Suse | — | Upgrade dracut-saltbootUpgrade ansible-docUpgrade ansibleUpgrade prometheus-blackbox_exporterUpgrade golang-github-qubitproducts-exporter_exporterUpgrade spacecmdUpgrade python3-hwdataUpgrade ansible-testUpgrade python2-hwdataUpgrade wireUpgrade golang-github-prometheus-node_exporter | Mar 18, 2022 | Apr 29, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub