Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Published Feb 6, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.30%
Description
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Affected products
No data.
Configuration 1
- < 2.14.4
- ≥ 2.15.0 · < 2.15.9
- ≥ 2.16.0 · < 2.16.3
- 8.0
- 9.0
Configuration 2
- 2.4
- 1.1
- 1.2
Running on/with
- 8.0
- 9.0
Configuration 3
- 38
- 39
No data.
Red Hat Ansible Automation Platform 2.4 for RHEL 8
ansible-core-1:2.15.9-1.el8ap
Fixed · RHSA-2024:0733
Red Hat Ansible Automation Platform 2.4 for RHEL 9
ansible-core-1:2.15.9-1.el9ap
Fixed · RHSA-2024:0733
Red Hat Enterprise Linux 8
ansible-core-0:2.16.3-2.el8
Fixed · RHSA-2024:3043
Red Hat Enterprise Linux 9
ansible-core-1:2.14.14-1.el9
Fixed · RHSA-2024:2246
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | ansible-core-1:2.15.9-1.el8ap | Fixed | RHSA-2024:0733 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | ansible-core-1:2.15.9-1.el9ap | Fixed | RHSA-2024:0733 |
| Red Hat Enterprise Linux 8 | ansible-core-0:2.16.3-2.el8 | Fixed | RHSA-2024:3043 |
| Red Hat Enterprise Linux 9 | ansible-core-1:2.14.14-1.el9 | Fixed | RHSA-2024:2246 |
No package ranges for this CVE.
Remediation
Vendor solution
Explicitly setting 'no_log' within the playbook will prevent the output from containing potentially sensitive information.
Red Hat mitigation
Explicitly setting 'no_log' within the playbook will prevent the output from containing potentially sensitive information.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 6, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.30% (0.00304) | 20.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.30% (0.00301) | 21.56th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00074) | 19.84th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.94th | v3 (v2023.03.01) |
| Jul 6, 2024 | 0.04% (0.00045) | 16.01th | v3 (v2023.03.01) |
| Apr 17, 2024 | 0.04% (0.00045) | 14.01th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.04% (0.00045) | 11.97th | v3 (v2023.03.01) |
References (17)
- https://access.redhat.com/errata/RHSA-2024:0733 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2024:2246 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:3043 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-0690 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2259013 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-h24r-m9qc-pvpg Advisory
- https://github.com/ansible/ansible/commit/6935c8e303440addd3871ecf8e04bde61080b032
- https://github.com/ansible/ansible/commit/78db3a3de6b40fb52d216685ae7cb903c609c3e1
- https://github.com/ansible/ansible/commit/b9a03bbf5a63459468baf8895ff74a62e9be4532
- https://github.com/ansible/ansible/commit/beb04bc2642c208447c5a936f94310528a1946b1
- https://github.com/ansible/ansible/pull/82565 Issue TrackingPatch
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible-core/PYSEC-2024-36.yaml
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IZQGCRDSZL7ONCULMB6ZUHOE4L44KIBP
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDYSWOCPZMNRU5LWKIEBW4WGWLMTU7WQ
- https://nvd.nist.gov/vuln/detail/CVE-2024-0690
- https://security.netapp.com/advisory/ntap-20250117-0001
- https://www.cve.org/CVERecord?id=CVE-2024-0690
Change history (0)
No recorded changes yet.