CVE Database
/

CVE-2024-8775

Back to search

CVE-2024-8775

Published: Sep 14, 2024

Modified: Nov 6, 2025

PUBLISHED

CVSS v3.1

5.5

MEDIUM

Description

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.

VendorProductVersions

Unknown

ansible-core

affected
1.0.0 - <= 2.17.4

Red Hat

Ansible Automation Platform Execution Environments

unaffected
3.0.1-96 - < *

Red Hat

Ansible Automation Platform Execution Environments

unaffected
3.0.1-95 - < *

Red Hat

Ansible Automation Platform Execution Environments

unaffected
2.9.27-32 - < *

Red Hat

Ansible Automation Platform Execution Environments

unaffected
2.14.13-21 - < *

Red Hat

Ansible Automation Platform Execution Environments

unaffected
2.17.6-2 - < *

Red Hat

Discovery 1 for RHEL 9

unaffected
1.12.0-1 - < *

Red Hat

Discovery 1 for RHEL 9

unaffected
1.12.0-1 - < *

Red Hat

Red Hat Ansible Automation Platform 2.4 for RHEL 8

unaffected
1:2.15.13-1.el8ap - < *

Red Hat

Red Hat Ansible Automation Platform 2.4 for RHEL 9

unaffected
1:2.15.13-1.el9ap - < *

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 8

unaffected
1:2.16.13-1.el8ap - < *

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 9

unaffected
1:2.16.13-1.el9ap - < *

Red Hat

Red Hat Enterprise Linux 10

All versions

Red Hat

Red Hat Enterprise Linux AI (RHEL AI)

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

References

RHSA-2024:10762
vendor-advisory
x_refsource_REDHAT
RHSA-2024:8969
vendor-advisory
x_refsource_REDHAT
RHSA-2024:9894
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1249
vendor-advisory
x_refsource_REDHAT
RHBZ#2312119
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now