CVE-2024-0690
published 2024-02-06CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.30%
22.0th percentile
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| debian | ansible-core | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_ansible_2.15.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ansible_2.17.0-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_ansible_2.14.12-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | ansible | < 2.14.4 | 2.14.4 |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 2.15.0 < 2.15.9 | 2.15.9 |
| redhat | ansible | >= 2.16.0 < 2.16.3 | 2.16.3 |
| redhat | ansible_automation_platform | — | — |
| redhat | ansible_developer | — | — |
| redhat | ansible_inside | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ansible-core information disclosure flaw
osv·2024-02-06
CVE-2024-0690 [MEDIUM] Ansible-core information disclosure flaw
Ansible-core information disclosure flaw
An information disclosure flaw was found in ansible-core due to a failure to respect the `ANSIBLE_NO_LOG` configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
OSV
CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios
osv·2024-02-06·CVSS 5.5
CVE-2024-0690 [MEDIUM] CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
GHSA
Ansible-core information disclosure flaw
ghsa·2024-02-06
CVE-2024-0690 [MEDIUM] CWE-116 Ansible-core information disclosure flaw
Ansible-core information disclosure flaw
An information disclosure flaw was found in ansible-core due to a failure to respect the `ANSIBLE_NO_LOG` configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
OSV
CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios
osv·2024-02-06
CVE-2024-0690 CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Microsoft
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
vendor_msrc·2024-02-13·CVSS 5.5
CVE-2024-0690 [MEDIUM] CWE-116 Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Marine
Red Hat
ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
vendor_redhat·2024-01-18·CVSS 5.0
CVE-2024-0690 [MEDIUM] CWE-117 ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Mitigation: Explicitly setting 'no_log' within the playbook will
Debian
CVE-2024-0690: ansible - An information disclosure flaw was found in ansible-core due to a failure to res...
vendor_debian·2024·CVSS 5.0
CVE-2024-0690 [MEDIUM] CVE-2024-0690: ansible - An information disclosure flaw was found in ansible-core due to a failure to res...
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Scope: local
bookworm: resolved (fixed in 5.4.0-1)
bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1)
forky: resolved (fixed in 5.4.0-1)
sid: resolved (fixed in 5.4.0-1)
trixie: resolved (fixed in 5.4.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-8775 ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging
bugzilla·2024-09-13·CVSS 5.5
CVE-2024-8775 [MEDIUM] CVE-2024-8775 ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging
CVE-2024-8775 ansible-core: Exposure of Sensitive Information in Ansible Vault Files Due to Improper Logging
This CVE affects Ansible and is similar to CVE-2024-0690. The vulnerability arises due to improper handling of sensitive variables loaded from Ansible Vault files, potentially leading to the exposure of secret data during execution.
Discussion:
This issue has been addressed in the following products:
Ansible Automation Platform Execution Environments
Via RHSA-2024:8969 https://access.redhat.com/errata/RHSA-2024:8969
---
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.5 for RHEL 8
Red Hat Ansible Automation Platform 2.5 for RHEL 9
Via RHSA-2024:9894 https://access.redhat.com/errata/RHSA-2024:9894
---
This issue has been addres
Bugzilla
CVE-2024-0690 ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
bugzilla·2024-01-18·CVSS 5.5
CVE-2024-0690 [MEDIUM] CVE-2024-0690 ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
CVE-2024-0690 ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
The `ANSIBLE_NO_LOG` environment variable configuration is currently being ignored. This impacts ansible-core 2.14, 2.15, and 2.16 supported releases (present in AAP 2.3 and 2.4)
There are workarounds, such as explicitly setting `no_log` within the playbook, but anyone relying on a global configuration is impacted.
Discussion:
Created ansible-core tracking bugs for this issue:
Affects: fedora-39 [bug 2259021]
---
Created ansible tracking bugs for this issue:
Affects: epel-8 [bug 2259029]
Affects: fedora-38 [bug 2259030]
Affects: fedora-39 [bug 2259031]
---
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.4 for RHEL 9
Red Hat Ansibl
https://access.redhat.com/errata/RHSA-2024:0733https://access.redhat.com/errata/RHSA-2024:2246https://access.redhat.com/errata/RHSA-2024:3043https://access.redhat.com/security/cve/CVE-2024-0690https://bugzilla.redhat.com/show_bug.cgi?id=2259013https://github.com/ansible/ansible/pull/82565https://access.redhat.com/errata/RHSA-2024:0733https://access.redhat.com/errata/RHSA-2024:2246https://access.redhat.com/errata/RHSA-2024:3043https://access.redhat.com/security/cve/CVE-2024-0690https://bugzilla.redhat.com/show_bug.cgi?id=2259013https://github.com/ansible/ansible/pull/82565https://lists.fedoraproject.org/archives/list/[email protected]/message/IZQGCRDSZL7ONCULMB6ZUHOE4L44KIBP/https://lists.fedoraproject.org/archives/list/[email protected]/message/VDYSWOCPZMNRU5LWKIEBW4WGWLMTU7WQ/https://security.netapp.com/advisory/ntap-20250117-0001/
2024-02-06
Published