CVE-2024-0690 is an information disclosure vulnerability in ansible-core, affecting products like fedoraproject and redhat. It occurs because the ANSIBLE_NO_LOG configuration is not always respected, potentially exposing sensitive information, such as decrypted secret values, in task outputs, particularly within loop items. Rated 5.5 MEDIUM, this flaw has low attack complexity and requires local access, leading to high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.14.4CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.15.0, < 2.15.9CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
>= 2.16.0, < 2.16.3CPE matchmatch criteria | cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-0690
Jun 11, 2024Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Feb 13, 2024Ansible-core information disclosure flaw
Feb 6, 2024ansible-core: possible information leak in tasks that ignore ANSIBLE_NO_LOG configuration
Jan 18, 2024