CVE-2024-0690

NameCVE-2024-0690
DescriptionAn information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1061156

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ansible (PTS)buster2.7.7+dfsg-1+deb10u1vulnerable
buster (security)2.7.7+dfsg-1+deb10u2vulnerable
bullseye2.10.7+merged+base+2.10.8+dfsg-1vulnerable
bookworm7.3.0+dfsg-1fixed
sid, trixie7.7.0+dfsg-3fixed
ansible-core (PTS)bookworm2.14.3-1vulnerable
sid, trixie2.14.13-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ansiblesource(unstable)5.4.0-1
ansible-coresource(unstable)(unfixed)1061156

Notes

[bookworm] - ansible-core <no-dsa> (Minor issue)
[bullseye] - ansible <no-dsa> (Minor issue)
ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
https://bugzilla.redhat.com/show_bug.cgi?id=2259013
https://github.com/ansible/ansible/pull/82565
https://github.com/ansible/ansible/commit/beb04bc2642c208447c5a936f94310528a1946b1 (stable-2.14)

Search for package or bug name: Reporting problems