CVE-2021-3620

Source
https://cve.org/CVERecord?id=CVE-2021-3620
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3620.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3620
Aliases
Downstream
Related
Published
2022-03-03T19:15:08.237Z
Modified
2026-02-15T08:05:11.608814Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

References

Affected packages

Git / github.com/ansible/ansible

Affected ranges

Type
GIT
Repo
https://github.com/ansible/ansible
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3620.json"