A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be. This issue only affects SSH/WinRM nodes (inventory service nodes).
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27022.json"
[ { "events": [ { "introduced": "2021.0.0" }, { "fixed": "2021.3.0" } ] }, { "events": [ { "introduced": "0" }, { "fixed": "2019.8.8" } ] } ]