CVE-2024-0690

NameCVE-2024-0690
DescriptionAn information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1061156

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ansible (PTS)jessie, jessie (lts)1.7.2+dfsg-2+deb8u3vulnerable
stretch (security), stretch (lts), stretch2.2.1.0-2+deb9u3vulnerable
buster2.7.7+dfsg-1+deb10u1vulnerable
buster (security)2.7.7+dfsg-1+deb10u2vulnerable
bullseye2.10.7+merged+base+2.10.8+dfsg-1vulnerable
bookworm7.3.0+dfsg-1fixed
sid, trixie9.5.1+dfsg-1fixed
ansible-core (PTS)bookworm2.14.3-1vulnerable
sid, trixie2.16.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ansiblesourcejessie(unfixed)end-of-life
ansiblesourcestretch(unfixed)end-of-life
ansiblesource(unstable)5.4.0-1
ansible-coresource(unstable)2.16.5-11061156

Notes

[bookworm] - ansible-core <no-dsa> (Minor issue)
[bullseye] - ansible <no-dsa> (Minor issue)
ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
https://bugzilla.redhat.com/show_bug.cgi?id=2259013
https://github.com/ansible/ansible/pull/82565
https://github.com/ansible/ansible/commit/beb04bc2642c208447c5a936f94310528a1946b1 (v2.14.14rc1)

Search for package or bug name: Reporting problems