Information Exposure Through an Error Message in Ansible - CVE-2021-3620

 

Information Exposure Through an Error Message in Ansible - CVE-2021-3620

Published: October 19, 2021


Vulnerability identifier: #VU57422
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3620
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in the Ansible Engine's ansible-connection module. The Ansible user credentials is disclosed by default in the traceback error message. A remote attacker with ability to intercept traffic can obtain user's credentials.


Affected software

Ansible
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE Manager Client Tools Beta for SLE Micro
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Manager Tools
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools Beta for SLE
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP
openSUSE Leap
ovirt-ansible-collection (Red Hat package)
ovirt-imageio (Red Hat package)
firewalld-prometheus-config
dracut-saltboot
golang-github-QubitProducts-exporter_exporter
wire
wire-debuginfo
prometheus-postgres_exporter
prometheus-blackbox_exporter
golang-github-lusitaniae-apache_exporter-debuginfo
golang-github-lusitaniae-apache_exporter
python3-zypp-plugin-spacewalk
zypp-plugin-spacewalk
supportutils-plugin-salt
golang-github-prometheus-node_exporter
golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter-debuginfo
otopi (Red Hat package)
python3-hwdata
python2-hwdata
ansible
ansible-test
ansible-doc
ansible-core (Red Hat package)
golang-github-prometheus-prometheus
python3-uyuni-common-libs
mgr-daemon
uyuni-proxy-systemd-services
mgr-virtualization-host
python3-mgr-virtualization-common
python3-mgr-virtualization-host
python3-spacewalk-client-tools
python3-spacewalk-client-setup
python3-spacewalk-check
spacewalk-check
spacewalk-client-setup
spacewalk-client-tools
spacecmd
python3-mgr-push
mgr-push
supportutils-plugin-susemanager-client
python3-rhnlib
python3-pyvmomi
grafana
grafana-debuginfo
Ansible Automation Platform
IBM Cloud Pak for Multicloud Management Security Services
Red Hat Virtualization Manager
IBM Edge Application Manager

How to mitigate CVE-2021-3620

Install updates from vendor's website.

Ansible - addressed in versions 2.9.27, 2.9.27-1.el7ae, 2.9.27-1.el8ae, 2.9.27-1.el8ap
ovirt-ansible-collection (Red Hat package) - update to 1.6.5-1.el8ev
Ansible Automation Platform - update to 2.0.1
ovirt-imageio (Red Hat package) - update to 2.3.0-1.el8ev
firewalld-prometheus-config - update to 0.1-159000.6.33.1
dracut-saltboot - addressed in versions 0.1.1657643023.0d694ce-150000.1.35.1, 0.1.1681904360.84ef141-159000.3.30.1
golang-github-QubitProducts-exporter_exporter - addressed in versions 0.4.0-150000.1.15.1, 0.4.0-159000.4.6.1
wire - update to 0.5.0-150000.1.6.1
wire-debuginfo - update to 0.5.0-150000.1.6.1
prometheus-postgres_exporter - update to 0.10.1-159000.3.6.1
prometheus-blackbox_exporter - addressed in versions 0.19.0-150000.1.11.1, 0.24.0-159000.3.6.1
golang-github-lusitaniae-apache_exporter-debuginfo - update to 1.0.0-159000.4.12.1
golang-github-lusitaniae-apache_exporter - update to 1.0.0-159000.4.12.1
python3-zypp-plugin-spacewalk - update to 1.0.13-150000.3.32.1
zypp-plugin-spacewalk - update to 1.0.13-150000.3.32.1
supportutils-plugin-salt - update to 1.2.2-159000.5.9.1
golang-github-prometheus-node_exporter - update to 1.3.0-150000.3.15.1
golang-github-boynux-squid_exporter - update to 1.6-159000.4.9.1
golang-github-boynux-squid_exporter-debuginfo - update to 1.6-159000.4.9.1
otopi (Red Hat package) - update to 1.9.6-2.el8ev
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
python3-hwdata - addressed in versions 2.3.5-150000.3.9.1, 2.3.5-159000.5.13.1
python2-hwdata - update to 2.3.5-150000.3.9.1
ansible - addressed in versions 2.9.27-1.el8, 2.9.27-1.fc33, 2.9.27-1.fc34, 2.9.27-1.fc35
ansible - addressed in versions 2.9.27-3.21.1, 2.9.27-150000.1.14.1, 2.9.27-159000.3.9.1
ansible-test - update to 2.9.27-150000.1.14.1
ansible-doc - addressed in versions 2.9.27-150000.1.14.1, 2.9.27-159000.3.9.1
ansible-core (Red Hat package) - update to 2.11.6-1.el8ap
golang-github-prometheus-prometheus - update to 2.45.0-159000.6.33.1
python3-uyuni-common-libs - addressed in versions 4.3.5-150000.1.24.1, 5.0.1-159000.3.33.1
mgr-daemon - update to 4.3.5-150000.1.35.1
uyuni-proxy-systemd-services - addressed in versions 4.3.6-150000.1.6.1, 5.0.1-159000.3.9.1
mgr-virtualization-host - update to 4.3.6-150000.1.32.1
python3-mgr-virtualization-common - update to 4.3.6-150000.1.32.1
python3-mgr-virtualization-host - update to 4.3.6-150000.1.32.1
python3-spacewalk-client-tools - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
python3-spacewalk-client-setup - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
python3-spacewalk-check - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacewalk-check - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacewalk-client-setup - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacewalk-client-tools - addressed in versions 4.3.11-150000.3.65.1, 5.0.1-159000.6.48.1
spacecmd - addressed in versions 4.3.14-150000.3.83.1, 5.0.1-159000.6.42.1
python3-mgr-push - update to 5.0.1-159000.4.21.1
mgr-push - update to 5.0.1-159000.4.21.1
supportutils-plugin-susemanager-client - update to 5.0.1-159000.6.15.1
python3-rhnlib - update to 5.0.1-159000.6.30.1
python3-pyvmomi - update to 6.7.3-159000.3.6.1
grafana - update to 9.5.8-159000.4.24.1
grafana-debuginfo - update to 9.5.8-159000.4.24.1

External References

Related Security Bulletins