CVE-2024-0690: Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
An information disclosure flaw was found in ansible-core due to a failure to respect the `ANSIBLE_NO_LOG` configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0690?
CVE-2024-0690 has been classified as an information disclosure vulnerability in ansible-core.
How do I fix CVE-2024-0690?
To remediate CVE-2024-0690, update ansible-core to versions 2.14.4, 2.15.9, or 2.16.3.
What software is affected by CVE-2024-0690?
CVE-2024-0690 affects versions of ansible-core up to 2.14.4, versions between 2.15.0 and up to 2.15.9, and between 2.16.0 and up to 2.16.3.
Can I still use ansible-core if it's affected by CVE-2024-0690?
While you can still use affected versions, it is strongly recommended to upgrade to mitigate the risk associated with CVE-2024-0690.
What products are also impacted by CVE-2024-0690?
In addition to ansible-core, IBM's Db2 on Cloud Pak for Data and applications using affected versions of ansible may also be impacted by CVE-2024-0690.