An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1oMjRyLW05cWMtcHZwZ84AA5HT

Ansible-core information disclosure flaw

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. It was discovered that information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 24 days ago
Updated: 16 days ago

CVSS Score: 5.0
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Identifiers: GHSA-h24r-m9qc-pvpg, CVE-2024-0690

Affected Packages

Versions: >= 2.15.0, < 2.15.9, >= 2.16.0, < 2.16.3, < 2.14.14
Fixed in: 2.15.9, 2.16.3, 2.14.14