CVE-2024-0690 - CVE House
Back to Database
Status published Medium CVE-2024-0690

Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration

Vulnerability Description

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0690

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Ansible Automation Platform 2.4 for RHEL 8, Red Hat Ansible Automation Platform 2.4 for RHEL 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Vulnerable Versions:
2.14.0, 2.15.0, 2.16.0, 1:2.15.9-1.el8ap, 1:2.15.9-1.el9ap, 0:2.16.3-2.el8, 1:2.14.14-1.el9

Timeline

Official Publish: February 6th, 2024
Last Modified: November 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.