CVE-2024-0690

A

n information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

History

04 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/IZQGCRDSZL7ONCULMB6ZUHOE4L44KIBP/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/VDYSWOCPZMNRU5LWKIEBW4WGWLMTU7WQ/ -

17 Jan 2025, 20:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250117-0001/ -

21 Nov 2024, 08:47

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2024:0733 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2024:0733 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2024:2246 - () https://access.redhat.com/errata/RHSA-2024:2246 -
References () https://access.redhat.com/errata/RHSA-2024:3043 - () https://access.redhat.com/errata/RHSA-2024:3043 -
References () https://access.redhat.com/security/cve/CVE-2024-0690 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2024-0690 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2259013 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2259013 - Issue Tracking
References () https://github.com/ansible/ansible/pull/82565 - Issue Tracking, Patch () https://github.com/ansible/ansible/pull/82565 - Issue Tracking, Patch
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 5.0

22 May 2024, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3043 -

30 Apr 2024, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2246 -

Information

Published : 2024-02-06 12:15

Updated : 2025-11-04 19:16


NVD link : CVE-2024-0690

Mitre link : CVE-2024-0690

CVE.ORG link : CVE-2024-0690


JSON object : View

CWE
CWE-117

Improper Output Neutralization for Logs

CWE-116

Improper Encoding or Escaping of Output