A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 3, 2022 |
| Centos_linux | — | Upgrade ovirt-ansible-collection | Nov 17, 2021 | Nov 16, 2021 |
| Debian | — | Upgrade ansibleUpgrade ansible-core | Jan 3, 2024 | Mar 3, 2022 |
| Freebsd | — | Upgrade py310-ansible2Upgrade py36-ansible2Upgrade py38-ansible-baseUpgrade py36-ansibleUpgrade py38-ansible-coreUpgrade py310-ansible-coreUpgrade py37-ansible2Upgrade py36-ansible-baseUpgrade py39-ansibleUpgrade py39-ansible-baseUpgrade py310-ansibleUpgrade py37-ansible-baseUpgrade py38-ansible2Upgrade py37-ansible-coreUpgrade py36-ansible-coreUpgrade py38-ansibleUpgrade py37-ansibleUpgrade py39-ansible2Upgrade py39-ansible-coreUpgrade py310-ansible-base | Nov 4, 2022 | Oct 11, 2021 |
| Redhat_linux | — | Upgrade ovirt-ansible-collection | Nov 17, 2021 | Nov 16, 2021 |
| Suse | — | Upgrade dracut-saltbootUpgrade golang-github-prometheus-node_exporterUpgrade prometheus-blackbox_exporterUpgrade wireUpgrade python3-hwdataUpgrade spacecmdUpgrade ansible-testUpgrade ansible-docUpgrade python2-hwdataUpgrade ansibleUpgrade golang-github-qubitproducts-exporter_exporter | Oct 26, 2022 | Mar 3, 2022 |
| Ubuntu | — | Upgrade ansible (Ubuntu Pro) | Mar 22, 2023 | Mar 3, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub