FlawAtlas
Search the atlas
CVE-2021-3620 Moderate

Ansible discloses sensitive information in traceback error message

Ansible is an IT automation system that handles configuration management, application deployment, cloud provisioning, ad-hoc task execution, network automation, and multi-node orchestration. A flaw was found in Ansible Engine's ansible-connection module where sensitive information, such as the Ansible user credentials, is disclosed by default in the traceback error message when Ansible receives an unexpected response from `set_options`. The highest threat from this vulnerability is confidentiality.

Exploit probability 0.4%
Published March 4, 2022
Required by Not available
Last source change February 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

65 explicit affected versions

PyPI ansible

232 explicit affected versions

PyPI ansible

232 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-4r65-35qq-ch8j

Ansible is an IT automation system that handles configuration management, application deployment, cloud provisioning, ad-hoc task execution, network automation, and multi-node orchestration. A flaw was found in Ansible Engine's ansible-connection module where sensitive information, such as the Ansible user credentials, is disclosed by default in the traceback error message when Ansible receives an unexpected response from `set_options`. The highest threat from this vulnerability is confidentiality.

View original source
Open Source Vulnerabilities PYSEC-2022-164

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

View original source
Open Source Vulnerabilities CVE-2021-3620

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

View original source

05 / REFERENCES

Further evidence