{"id":"GHSA-fh5v-5f35-2rv2","summary":"Insertion of Sensitive Information into Log File in ansible","details":"A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.","aliases":["CVE-2021-20180"],"modified":"2023-11-08T04:04:34.858726Z","published":"2022-03-17T00:00:44Z","database_specific":{"nvd_published_at":"2022-03-16T15:15:00Z","cwe_ids":["CWE-532"],"github_reviewed":true,"github_reviewed_at":"2022-06-29T12:15:59Z","severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20180"},{"type":"WEB","url":"https://github.com/ansible/ansible/pull/73242"},{"type":"WEB","url":"https://github.com/ansible/ansible/pull/73243"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1915808"},{"type":"PACKAGE","url":"https://github.com/ansible/ansible"},{"type":"WEB","url":"https://github.com/ansible/ansible/blob/v2.8.19/changelogs/CHANGELOG-v2.8.rst"},{"type":"WEB","url":"https://github.com/ansible/ansible/blob/v2.9.18/changelogs/CHANGELOG-v2.9.rst"},{"type":"WEB","url":"https://github.com/ansible/ansible/tree/v2.7.18/lib/ansible/modules/source_control"},{"type":"WEB","url":"https://github.com/ansible/ansible/tree/v2.8.0a1/lib/ansible/modules/source_control"}],"affected":[{"package":{"name":"ansible","ecosystem":"PyPI","purl":"pkg:pypi/ansible"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0a1"},{"fixed":"2.8.19"}]}],"versions":["2.8.0","2.8.0a1","2.8.0b1","2.8.0rc1","2.8.0rc2","2.8.0rc3","2.8.1","2.8.10","2.8.11","2.8.12","2.8.13","2.8.14","2.8.15","2.8.16","2.8.16rc1","2.8.17","2.8.17rc1","2.8.18","2.8.18rc1","2.8.19rc1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","2.8.8","2.8.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-fh5v-5f35-2rv2/GHSA-fh5v-5f35-2rv2.json"}},{"package":{"name":"ansible","ecosystem":"PyPI","purl":"pkg:pypi/ansible"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.0b1"},{"fixed":"2.9.18"}]}],"versions":["2.9.0","2.9.0b1","2.9.0rc1","2.9.0rc2","2.9.0rc3","2.9.0rc4","2.9.0rc5","2.9.1","2.9.10","2.9.11","2.9.12","2.9.13","2.9.14","2.9.14rc1","2.9.15","2.9.15rc1","2.9.16","2.9.16rc1","2.9.17","2.9.17rc1","2.9.18rc1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.9.7","2.9.8","2.9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-fh5v-5f35-2rv2/GHSA-fh5v-5f35-2rv2.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}