cbcvebase.
CVE-2024-8775
published 2024-09-14

CVE-2024-8775: A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This…

PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.27%
19.1th percentile
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 5.4.0-1 (bookworm)ansible 5.4.0-1 (bookworm)
debianansible-core< ansible 5.4.0-1 (bookworm)ansible 5.4.0-1 (bookworm)
msrcazl3_ansible_2.17.0-1_on_azure_linux_3.0
msrcazl3_ansible_2.17.11-1_on_azure_linux_3.0
msrccbl2_ansible_2.14.18-1_on_cbl_mariner_2.0
redhatansible>= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u22.10.7+merged+base+2.10.17+dfsg-0+deb11u2
redhatansible>= 0 < 5.4.0-15.4.0-1
redhatansible>= 0 < 5.4.0-15.4.0-1
redhatansible>= 0 < 5.4.0-15.4.0-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.