Ansible-core information disclosure flaw
An information disclosure flaw was found in ansible-core due to a failure to respect the `ANSIBLE_NO_LOG` configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
02 / AFFECTED SOFTWARE
Affected packages
30 explicit affected versions
122 explicit affected versions
141 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
An information disclosure flaw was found in ansible-core due to a failure to respect the `ANSIBLE_NO_LOG` configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
05 / REFERENCES
Further evidence
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2024:0733
- https://access.redhat.com/errata/RHSA-2024:2246
- https://access.redhat.com/errata/RHSA-2024:3043
- https://access.redhat.com/security/cve/CVE-2024-0690
- https://bugzilla.redhat.com/show_bug.cgi?id=2259013
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0690.json
- https://github.com/ansible/ansible/pull/82565
- https://lists.fedoraproject.org/archives/list/[email protected]/message/IZQGCRDSZL7ONCULMB6ZUHOE4L44KIBP/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VDYSWOCPZMNRU5LWKIEBW4WGWLMTU7WQ/
- https://nvd.nist.gov/vuln/detail/CVE-2024-0690
- https://security.netapp.com/advisory/ntap-20250117-0001/
- https://www.ansible.com/
- https://github.com/advisories/GHSA-h24r-m9qc-pvpg
- https://github.com/ansible/ansible
- https://github.com/ansible/ansible/commit/6935c8e303440addd3871ecf8e04bde61080b032
- https://github.com/ansible/ansible/commit/78db3a3de6b40fb52d216685ae7cb903c609c3e1
- https://github.com/ansible/ansible/commit/b9a03bbf5a63459468baf8895ff74a62e9be4532
- https://github.com/ansible/ansible/commit/beb04bc2642c208447c5a936f94310528a1946b1
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible-core/PYSEC-2024-36.yaml
- https://lists.fedoraproject.org/archives/list/[email protected]/message/IZQGCRDSZL7ONCULMB6ZUHOE4L44KIBP
- https://lists.fedoraproject.org/archives/list/[email protected]/message/VDYSWOCPZMNRU5LWKIEBW4WGWLMTU7WQ
- https://security.netapp.com/advisory/ntap-20250117-0001