Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-8775

Опубликовано: 14 сент. 2024
Источник: debian

Описание

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansible-corefixed2.17.5-5package
ansible-corefixed2.14.18-0+deb12u1bookwormpackage
ansiblefixed5.4.0-1package

Примечания

  • ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid

  • https://bugzilla.redhat.com/show_bug.cgi?id=2312119

  • Ansible bug: https://github.com/ansible/ansible/pull/84179

  • Fixed by: https://github.com/ansible/ansible/commit/23f8639a4b01f6437f241d835efb68b8b7150575 (v2.18.0rc2)

  • Fixed by: https://github.com/ansible/ansible/commit/4a654435470c88a5732af5d647d0014b2eea2557 (v2.17.6rc1)

  • Fixed by: https://github.com/ansible/ansible/commit/62682c30298cc18c029438d524aee3376497fd7c (v2.14.18rc1)

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

CVSS3: 5.5
redhat
почти 2 года назад

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

CVSS3: 5.5
nvd
почти 2 года назад

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

CVSS3: 5.5
msrc
около 1 года назад

Ansible-core: exposure of sensitive information in ansible vault files due to improper logging

suse-cvrf
больше 1 года назад

Recommended update 4.3.15 for Multi-Linux Manager Client Tools