An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade ansible-testUpgrade ansible-core | May 8, 2024 | Feb 6, 2024 |
| Amazon_linux_2023 | — | Upgrade ansible-testUpgrade ansible-core | Feb 17, 2025 | Jan 18, 2024 |
| Debian | — | Upgrade ansible-coreUpgrade ansible | Jul 30, 2024 | Feb 6, 2024 |
| Oracle_linux | — | Upgrade ansible-testUpgrade ansible-core | May 7, 2024 | Jan 18, 2024 |
| Redhat_linux | — | Upgrade ansible-testUpgrade ansible-core | May 1, 2024 | Feb 6, 2024 |
| Rocky_linux | — | Upgrade ansible-testUpgrade ansible-core | Jul 31, 2025 | May 7, 2025 |
| Suse | — | Upgrade ansible-coreUpgrade ansible-docUpgrade ansibleUpgrade ansible-test | May 7, 2024 | Feb 6, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub