Inclusion of Sensitive Information in Log Files in Ansible Automation Platform and Ansible Tower - CVE-2021-3447
Published: May 10, 2021
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files. A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. A local user can read the log files and gain access to sensitive data.
Affected software
Ansible Tower
Red Hat Virtualization Host
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE Manager Client Tools Beta for SLE Micro
SUSE Linux Enterprise Micro
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Manager Tools
SUSE Manager Client Tools Beta for SLE
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP
openSUSE Leap
scap-security-guide (Red Hat package)
imgbased (Red Hat package)
ovirt-ansible-collection (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
python-ovirt-engine-sdk4 (Red Hat package)
firewalld-prometheus-config
dracut-saltboot
golang-github-QubitProducts-exporter_exporter
wire-debuginfo
wire
prometheus-postgres_exporter
prometheus-blackbox_exporter
golang-github-lusitaniae-apache_exporter-debuginfo
golang-github-lusitaniae-apache_exporter
python3-zypp-plugin-spacewalk
zypp-plugin-spacewalk
fcoe-utils (Red Hat package)
vhostmd (Red Hat package)
supportutils-plugin-salt
golang-github-prometheus-node_exporter
golang-github-boynux-squid_exporter-debuginfo
golang-github-boynux-squid_exporter
ovirt-imageio (Red Hat package)
python3-hwdata
python2-hwdata
ansible
ansible-test
ansible-doc
ovirt-openvswitch (Red Hat package)
golang-github-prometheus-prometheus
python3-uyuni-common-libs
mgr-daemon
uyuni-proxy-systemd-services
mgr-virtualization-host
python3-mgr-virtualization-common
python3-mgr-virtualization-host
python3-spacewalk-client-setup
python3-spacewalk-client-tools
spacewalk-check
spacewalk-client-setup
spacewalk-client-tools
python3-spacewalk-check
spacecmd
mgr-push
python3-mgr-push
supportutils-plugin-susemanager-client
python3-rhnlib
python3-pyvmomi
grafana-debuginfo
grafana
Ansible
Red Hat Virtualization
Red Hat Virtualization Manager
Red Hat OpenShift Container Platform
How to mitigate CVE-2021-3447
Ansible Tower - update to 3.8.2
scap-security-guide (Red Hat package) - update to 0.1.54-2.el8ev
imgbased (Red Hat package) - update to 1.2.21-1.el8ev
ovirt-ansible-collection (Red Hat package) - update to 1.5.3-1.el8ev
Ansible - addressed in versions 2.9.20-1.el7ae, 2.9.20-1.el8ae, 2.9.21-1.el8ae
redhat-release-virtualization-host (Red Hat package) - update to 4.4.7-3.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.4.7-20210715.1.el8_4
python-ovirt-engine-sdk4 (Red Hat package) - update to 4.4.13-1.el8ev
Red Hat OpenShift Container Platform - update to 4.6.27
firewalld-prometheus-config - update to 0.1-159000.6.33.1
dracut-saltboot - addressed in versions 0.1.1657643023.0d694ce-150000.1.35.1, 0.1.1681904360.84ef141-159000.3.30.1
golang-github-QubitProducts-exporter_exporter - addressed in versions 0.4.0-150000.1.15.1, 0.4.0-159000.4.6.1
wire-debuginfo - update to 0.5.0-150000.1.6.1
wire - update to 0.5.0-150000.1.6.1
prometheus-postgres_exporter - update to 0.10.1-159000.3.6.1
prometheus-blackbox_exporter - addressed in versions 0.19.0-150000.1.11.1, 0.24.0-159000.3.6.1
golang-github-lusitaniae-apache_exporter-debuginfo - update to 1.0.0-159000.4.12.1
golang-github-lusitaniae-apache_exporter - update to 1.0.0-159000.4.12.1
python3-zypp-plugin-spacewalk - update to 1.0.13-150000.3.32.1
zypp-plugin-spacewalk - update to 1.0.13-150000.3.32.1
fcoe-utils (Red Hat package) - update to 1.0.33-3.git848bcc6.el8
vhostmd (Red Hat package) - update to 1.1-5.el8
supportutils-plugin-salt - update to 1.2.2-159000.5.9.1
golang-github-prometheus-node_exporter - update to 1.3.0-150000.3.15.1
golang-github-boynux-squid_exporter-debuginfo - update to 1.6-159000.4.9.1
golang-github-boynux-squid_exporter - update to 1.6-159000.4.9.1
ovirt-imageio (Red Hat package) - update to 2.2.0-1.el8ev
python3-hwdata - addressed in versions 2.3.5-150000.3.9.1, 2.3.5-159000.5.13.1
python2-hwdata - update to 2.3.5-150000.3.9.1
ansible - addressed in versions 2.9.20-1.el7, 2.9.20-1.el8, 2.9.20-1.fc32, 2.9.20-1.fc33, 2.9.20-1.fc34, 2.9.21-1.el7
ansible - addressed in versions 2.9.22-3.18.1, 2.9.27-150000.1.14.1, 2.9.27-159000.3.9.1
ansible-test - update to 2.9.27-150000.1.14.1
ansible-doc - addressed in versions 2.9.27-150000.1.14.1, 2.9.27-159000.3.9.1
ovirt-openvswitch (Red Hat package) - update to 2.11-1.el8ev
golang-github-prometheus-prometheus - update to 2.45.0-159000.6.33.1
python3-uyuni-common-libs - addressed in versions 4.3.5-150000.1.24.1, 5.0.1-159000.3.33.1
mgr-daemon - update to 4.3.5-150000.1.35.1
uyuni-proxy-systemd-services - addressed in versions 4.3.6-150000.1.6.1, 5.0.1-159000.3.9.1
mgr-virtualization-host - update to 4.3.6-150000.1.32.1
python3-mgr-virtualization-common - update to 4.3.6-150000.1.32.1
python3-mgr-virtualization-host - update to 4.3.6-150000.1.32.1
python3-spacewalk-client-setup - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
python3-spacewalk-client-tools - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacewalk-check - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacewalk-client-setup - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacewalk-client-tools - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
python3-spacewalk-check - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacecmd - addressed in versions 4.3.14-150000.3.83.1, 5.0.1-159000.6.42.1
mgr-push - update to 5.0.1-159000.4.21.1
python3-mgr-push - update to 5.0.1-159000.4.21.1
supportutils-plugin-susemanager-client - update to 5.0.1-159000.6.15.1
python3-rhnlib - update to 5.0.1-159000.6.30.1
python3-pyvmomi - update to 6.7.3-159000.3.6.1
grafana-debuginfo - update to 9.5.8-159000.4.24.1
grafana - update to 9.5.8-159000.4.24.1
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=1939349
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RUTGO4RS4ZXZSPBU2CHVPT75IAFVTTL3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MS4VPUYVLGSAKOX26IT52BSMEZRZ3KS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JBZ75MAMVQVZROPYHMRDQKPPVASP63DG/
Related Security Bulletins
- Information disclosure via log files in Red Hat Ansible Automation Platform and Ansible Tower
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Multiple vulnerabilities in Red Hat Virtualization
- RHV Engine and Host Common Packages security update
- SUSE update for ansible
- SUSE update for Important for SUSE Manager Client Tools
- Ansible Engine 2 update for ansible
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- SUSE update for Security Beta update for SUSE Manager Client Tools and Salt
- Ansible Engine 2Red Hat Product Security has rated this update as having a security impactof Moderate update for ansible
- Fedora EPEL 8 update for ansible
- Fedora 33 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora 34 update for ansible
- Fedora 32 update for ansible
- Fedora EPEL 7 update for ansible