← Back

CVE-2024-0690

nvd nist
Published: Feb 6, 2024Modified: Nov 4, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Affected (8)

4 products
Ansible
Ansible Automation Platform
Ansible Developer
Ansible Inside
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Before 2.14.4
From 2.15.0 to 2.15.9
From 2.16.0 to 2.16.3
Configuration B
3 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 2.4
Version 1.1
Version 1.2
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0
Redhat
Enterprise Linux
Version 9.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39

References (15)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.