CVE-2024-0690

NameCVE-2024-0690
DescriptionAn information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1061156

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ansible (PTS)jessie, jessie (lts)1.7.2+dfsg-2+deb8u3vulnerable
stretch (security), stretch (lts), stretch2.2.1.0-2+deb9u3vulnerable
buster (security), buster, buster (lts)2.7.7+dfsg-1+deb10u2vulnerable
bullseye2.10.7+merged+base+2.10.17+dfsg-0+deb11u1fixed
bookworm7.7.0+dfsg-3+deb12u1fixed
sid, trixie10.5.0+dfsg-2fixed
ansible-core (PTS)bookworm2.14.16-0+deb12u1fixed
sid, trixie2.17.5-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ansiblesourcestretch(unfixed)end-of-life
ansiblesourcebullseye2.10.7+merged+base+2.10.17+dfsg-0+deb11u1
ansiblesource(unstable)5.4.0-1
ansible-coresourcebookworm2.14.16-0+deb12u1
ansible-coresource(unstable)2.16.5-11061156

Notes

ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
https://bugzilla.redhat.com/show_bug.cgi?id=2259013
https://github.com/ansible/ansible/pull/82565
https://github.com/ansible/ansible/commit/beb04bc2642c208447c5a936f94310528a1946b1 (v2.14.14rc1)

Search for package or bug name: Reporting problems