First published: Fri Sep 13 2024(Updated: )
This CVE affects Ansible and is similar to <a href="https://access.redhat.com/security/cve/CVE-2024-0690">CVE-2024-0690</a>. The vulnerability arises due to improper handling of sensitive variables loaded from Ansible Vault files, potentially leading to the exposure of secret data during execution.
Affected Software | Affected Version | How to fix |
---|---|---|
Ansible |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2312119 is classified as high due to potential exposure of sensitive data.
To fix REDHAT-BUG-2312119, update to the latest version of Ansible that includes security patches addressing this vulnerability.
The potential impacts of REDHAT-BUG-2312119 include unauthorized access to sensitive information stored in Ansible Vault files.
REDHAT-BUG-2312119 affects all versions of Ansible that improperly handle sensitive variables from Vault files.
To mitigate risks associated with REDHAT-BUG-2312119, restrict access to Ansible Vault files and apply relevant security updates promptly.