[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2ANSIBLE2-2023-004 --- ansible

ID: oval:org.secpod.oval:def:1701714Date: (C)2023-10-26   (M)2024-01-02
Class: PATCHFamily: unix




A flaw was found in ansible. The 'authkey' and 'privkey' credentials are disclosed by default and not protected by no_log feature when using the snmp_facts module. Attackers could take advantage of this information to steal the SNMP credentials. The highest threat from this vulnerability is to data confidentiality. A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality. A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality

Platform:
Amazon Linux 2
Product:
ansible
Reference:
ALAS2ANSIBLE2-2023-004
CVE-2021-20178
CVE-2021-20180
CVE-2021-20191
CVE    3
CVE-2021-20180
CVE-2021-20178
CVE-2021-20191
CPE    2
cpe:/a:ansibleworks:ansible
cpe:/o:amazon:linux:2

© SecPod Technologies