CVE-2024-0690: Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLENOLOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Other sources
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLENOLOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
— IBM
The ANSIBLENOLOG environment variable configuration is currently being ignored. This impacts ansible-core 2.14, 2.15, and 2.16 supported releases (present in AAP 2.3 and 2.4)
There are workarounds, such as explicitly setting nolog within the playbook, but anyone relying on a global configuration is impacted.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0690?
CVE-2024-0690 has been classified as an information disclosure vulnerability in ansible-core.
How do I fix CVE-2024-0690?
To remediate CVE-2024-0690, update ansible-core to versions 2.14.4, 2.15.9, or 2.16.3.
What software is affected by CVE-2024-0690?
CVE-2024-0690 affects versions of ansible-core up to 2.14.4, versions between 2.15.0 and up to 2.15.9, and between 2.16.0 and up to 2.16.3.
Can I still use ansible-core if it's affected by CVE-2024-0690?
While you can still use affected versions, it is strongly recommended to upgrade to mitigate the risk associated with CVE-2024-0690.
What products are also impacted by CVE-2024-0690?
In addition to ansible-core, IBM's Db2 on Cloud Pak for Data and applications using affected versions of ansible may also be impacted by CVE-2024-0690.