Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-8775

Опубликовано: 14 сент. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansible-corefixed2.17.5-5package
ansible-corefixed2.14.18-0+deb12u1bookwormpackage
ansiblefixed5.4.0-1package

Примечания

  • ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid

  • https://bugzilla.redhat.com/show_bug.cgi?id=2312119

  • Ansible bug: https://github.com/ansible/ansible/pull/84179

  • Fixed by: https://github.com/ansible/ansible/commit/23f8639a4b01f6437f241d835efb68b8b7150575 (v2.18.0rc2)

  • Fixed by: https://github.com/ansible/ansible/commit/4a654435470c88a5732af5d647d0014b2eea2557 (v2.17.6rc1)

  • Fixed by: https://github.com/ansible/ansible/commit/62682c30298cc18c029438d524aee3376497fd7c (v2.14.18rc1)

EPSS

Процентиль: 6%
0.00027
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
11 месяцев назад

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

CVSS3: 5.5
redhat
11 месяцев назад

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

CVSS3: 5.5
nvd
11 месяцев назад

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

CVSS3: 5.5
msrc
около 1 месяца назад

Описание отсутствует

suse-cvrf
6 месяцев назад

Recommended update 4.3.15 for Multi-Linux Manager Client Tools

EPSS

Процентиль: 6%
0.00027
Низкий