Back

MEDIUM

Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration

Published Feb 6, 2024

Description

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Affected products

Remediation

Vendor solution

Explicitly setting 'no_log' within the playbook will prevent the output from containing potentially sensitive information.

Red Hat mitigation

Explicitly setting 'no_log' within the playbook will prevent the output from containing potentially sensitive information.

Metrics

Weaknesses (2)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 6, 2024
Updated Nov 6, 2025
Reserved Jan 18, 2024
CISA Vulnrichment
Updated Feb 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 18, 2024
GHSA-H24R-M9QC-PVPG