Vulnerability Description
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible | < 2.14.4 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Ansible Automation Platform | 2.4 |
| Redhat | Ansible Developer | 1.1 |
| Redhat | Ansible Inside | 1.2 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2024:0733Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:2246
- https://access.redhat.com/errata/RHSA-2024:3043
- https://access.redhat.com/security/cve/CVE-2024-0690Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2259013Issue Tracking
- https://github.com/ansible/ansible/pull/82565Issue TrackingPatch
- https://access.redhat.com/errata/RHSA-2024:0733Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:2246
- https://access.redhat.com/errata/RHSA-2024:3043
- https://access.redhat.com/security/cve/CVE-2024-0690Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2259013Issue Tracking
- https://github.com/ansible/ansible/pull/82565Issue TrackingPatch
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://security.netapp.com/advisory/ntap-20250117-0001/
FAQ
What is CVE-2024-0690?
CVE-2024-0690 is a vulnerability with a CVSS score of 5.0 (MEDIUM). An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, s...
How severe is CVE-2024-0690?
CVE-2024-0690 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0690?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Ansible, Redhat Enterprise Linux, Redhat Ansible Automation Platform, Redhat Ansible Developer, Redhat Ansible Inside.