CVE-2024-8775Medium· 5.5▾ SunlitA flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.3%
Last analysed / modified upstream
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
ansible-core >= 2.17.0b1, < 2.17.6ansible-core < 2.16.13Patched in:
ansible-core 2.17.6ansible-core 2.16.13Source: https://osv.dev/vulnerability/GHSA-jpxc-vmjf-9fcj
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-9902Medium· 6.3ansible-core Incorrect Authorization vulnerability
CVE-2026-11332High· 7.8A flaw was found in ansible-core
CVE-2026-66780Medium· 6.5A flaw was found in the submariner-operator component
CVE-2026-81320Medium· 5.5A flaw was found in hawtio-operator
CVE-2023-4237Medium· 6.5Ansible may expose private key
CVE-2023-5764Medium· 6.6Ansible template injection vulnerability