PT-2021-8095 · Red Hat+3 · Ansible Tower+4
Chen Zhi
+2
·
Published
2021-01-17
·
Updated
2025-05-04
·
CVE-2021-3447
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Ansible Automation Platform versions prior to 1.2.2
Ansible Tower versions prior to 3.8.2
Description
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the
no log feature. An attacker can take advantage of this information to steal those credentials, provided when they have access to the log files containing them. The highest threat from this vulnerability is to data confidentiality.Recommendations
For Red Hat Ansible Automation Platform versions prior to 1.2.2, update to version 1.2.2 or later to resolve the issue.
For Ansible Tower versions prior to 3.8.2, update to version 3.8.2 or later to resolve the issue.
As a temporary workaround, consider disabling the verbose mode to minimize the risk of exploitation.
Restrict access to the log files containing sensitive information to prevent unauthorized access.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible-Core
Ansible Tower
Astra Linux
Red Hat Ansible Automation Platform
Suse