PT-2022-9169 · Ansible+2 · Ansible+3

Tapas Jena

·

Published

2021-02-23

·

Updated

2026-06-03

·

CVE-2021-20180

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ansible (affected versions not specified)
Description A flaw in the ansible module discloses credentials in the console log by default when using the bitbucket pipeline variable module, allowing an attacker to steal bitbucket pipeline credentials. The highest threat from this issue is to confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1383
ALT-PU-2021-1395
ALT-PU-2021-1800
CVE-2021-20180
GHSA-FH5V-5F35-2RV2
MGASA-2021-0132
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2022_3178-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
OPENSUSE-SU-2026:10944-1
RHSA-2021:0663
RHSA-2021:0664
RHSA-2021:2180
ROSA-SA-2024-2334
ROSA-SA-2024-2532
SUSE-SU-2021:2121-1
SUSE-SU-2022:3178-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Ansible-Core
Suse
Ansible