A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 29, 2021 |
| Centos_linux | — | Upgrade rubygem-ovirt-engine-sdk4-docUpgrade ovirt-ansible-collectionUpgrade rubygem-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4Upgrade python3-ovirt-engine-sdk4-debuginfoUpgrade rubygem-ovirt-engine-sdk4-debugsourceUpgrade python-ovirt-engine-sdk4-debugsourceUpgrade python3-ovirt-engine-sdk4 | Jun 2, 2021 | Apr 29, 2021 |
| Debian | — | Upgrade ansible | Aug 9, 2021 | Apr 29, 2021 |
| Redhat_linux | — | Upgrade rubygem-ovirt-engine-sdk4-debuginfoUpgrade python3-ovirt-engine-sdk4-debuginfoUpgrade ovirt-ansible-collectionUpgrade python3-ovirt-engine-sdk4Upgrade python-ovirt-engine-sdk4-debugsourceUpgrade rubygem-ovirt-engine-sdk4Upgrade rubygem-ovirt-engine-sdk4-docUpgrade rubygem-ovirt-engine-sdk4-debugsource | Jun 2, 2021 | Apr 29, 2021 |
| Suse | — | Upgrade ansible-docUpgrade ansibleUpgrade spacecmdUpgrade dracut-saltbootUpgrade prometheus-blackbox_exporterUpgrade golang-github-qubitproducts-exporter_exporterUpgrade golang-github-prometheus-node_exporterUpgrade wireUpgrade python2-hwdataUpgrade ansible-testUpgrade python3-hwdata | Mar 18, 2022 | Apr 29, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub