QID 352253

Date Published: 2021-03-25

QID 352253: Amazon Linux Security Advisory for ansible: ALAS2-2021-1613

<DIV> Issue Overview:

A flaw was found in ansible. The 'authkey' and 'privkey' credentials are disclosed by default and not protected by no_log feature when using the snmp_facts module. Attackers could take advantage of this information to steal the SNMP credentials. The highest threat from this vulnerability is to data confidentiality. (CVE-2021-20178 )

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality. (CVE-2021-20180 )

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. (CVE-2021-20191 )

</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Please refer to Amazon advisory ALAS-2021-1613 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352253

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1613 Amazon Linux 2 ansible (2.9.18-1.amzn2) on noarch URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1613.html
    ALAS-2021-1613 Amazon Linux 2 ansible (2.9.18-1.amzn2) on src URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1613.html
    © CVE.report 2026 |

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report