{"id":"CVE-2021-3620","aliases":["GHSA-4r65-35qq-ch8j","PYSEC-2022-164"],"url":"https://o3.security/vulnerability/CVE-2021-3620","summary":"Ansible discloses sensitive information in traceback error message","details":"A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.","published":"2022-03-03T19:15:08.237Z","modified":"2026-08-07T11:49:13.887373168Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.9.27"}],"fix":{"url":"https://github.com/ansible/ansible/commit/fe28767970c8ec62aabe493c46b53a5de1e5fac0","label":"ansible/ansible@fe28767"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html"},{"type":"ADVISORY","url":"https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#security-fixes"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1975767"},{"type":"FIX","url":"https://github.com/ansible/ansible/commit/fe28767970c8ec62aabe493c46b53a5de1e5fac0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:49:13.887373168Z"}}