DescriptionAn information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1061156

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ansible (PTS)bullseye2.10.7+merged+base+2.10.8+dfsg-1vulnerable
sid, trixie10.1.0+dfsg-1fixed
ansible-core (PTS)bookworm2.14.3-1vulnerable
sid, trixie2.17.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


[bookworm] - ansible-core <no-dsa> (Minor issue)
[bullseye] - ansible <no-dsa> (Minor issue)
ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid (v2.14.14rc1)

Search for package or bug name: Reporting problems