{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2021/cve-2021-3447-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-03T13:44:01Z",
      "generator": {
        "date": "2026-08-03T13:44:00Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2021-3447-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2021-04-01T18:15:00Z",
      "revision_history": [
        {
          "date": "2021-04-01T18:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-31T18:31:03Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-03T13:44:01Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2021-3447"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ansible-0:2.7.7+dfsg-1+deb10u2.all",
                "product": {
                  "name": "ansible-0:2.7.7+dfsg-1+deb10u2.all",
                  "product_id": "ansible-0:2.7.7+dfsg-1+deb10u2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/ansible@2.7.7%2Bdfsg-1%2Bdeb10u2?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ansible-doc-0:2.7.7+dfsg-1+deb10u2.all",
                "product": {
                  "name": "ansible-doc-0:2.7.7+dfsg-1+deb10u2.all",
                  "product_id": "ansible-doc-0:2.7.7+dfsg-1+deb10u2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/ansible-doc@2.7.7%2Bdfsg-1%2Bdeb10u2?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
                "product": {
                  "name": "ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
                  "product_id": "ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ansible@2.7.7%2Bdfsg-1%2Bdeb10u2%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
                "product": {
                  "name": "ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
                  "product_id": "ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/ansible-doc@2.7.7%2Bdfsg-1%2Bdeb10u2%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all"
        },
        "product_reference": "ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all"
        },
        "product_reference": "ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-0:2.7.7+dfsg-1+deb10u2.all as a component of Debian 10",
          "product_id": "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2.all"
        },
        "product_reference": "ansible-0:2.7.7+dfsg-1+deb10u2.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-doc-0:2.7.7+dfsg-1+deb10u2.all as a component of Debian 10",
          "product_id": "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2.all"
        },
        "product_reference": "ansible-doc-0:2.7.7+dfsg-1+deb10u2.all",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3447",
      "cwe": {
        "id": "CWE-532",
        "name": "Insertion of Sensitive Information into Log File"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. An attacker can take advantage of this information to steal those credentials, provided when they have access to the log files containing them. The highest threat from this vulnerability is to data confidentiality. This flaw affects Red Hat Ansible Automation Platform in versions before 1.2.2 and Ansible Tower in versions before 3.8.2.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
          "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2.all",
          "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
          "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-3447"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=1939349",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1939349"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MS4VPUYVLGSAKOX26IT52BSMEZRZ3KS/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MS4VPUYVLGSAKOX26IT52BSMEZRZ3KS/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBZ75MAMVQVZROPYHMRDQKPPVASP63DG/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBZ75MAMVQVZROPYHMRDQKPPVASP63DG/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUTGO4RS4ZXZSPBU2CHVPT75IAFVTTL3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RUTGO4RS4ZXZSPBU2CHVPT75IAFVTTL3/"
        }
      ],
      "release_date": "2021-04-01T18:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-03T11:36:55.303282Z",
          "details": "This is a local-only information disclosure that requires an attacker to already have read access to Ansible job logs on managed hosts or to the controller’s verbose output; it provides no code execution or privilege escalation and affects confidentiality only. It is further limited to legacy releases (Ansible Automation Platform before 1.2.2 and Ansible Tower before 3.8.2) and scenarios where secrets are passed as module parameters, making it low-priority in centrally managed VM/server deployments.",
          "product_ids": [
            "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
            "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2.all",
            "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
            "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2.all"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 2.1,
            "baseSeverity": "LOW",
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "NONE",
            "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
            "Debian-10:ansible-0:2.7.7+dfsg-1+deb10u2.all",
            "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2+tuxcare.els1.all",
            "Debian-10:ansible-doc-0:2.7.7+dfsg-1+deb10u2.all"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}