Inclusion of Sensitive Information in Log Files in Ansible - CVE-2024-8775

 

Inclusion of Sensitive Information in Log Files in Ansible - CVE-2024-8775

Published: November 27, 2024


Vulnerability identifier: #VU100999
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8775
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to software stores sensitive information into log files. A local user can read the log files and gain access to sensitive data.


Affected software

Ansible
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Oracle Solaris
IBM Fusion HCI
Ansible Automation Platform
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Application Suite - Manage Component
Guardium Data Security Center (GDSC)
IBM Security SOAR
receptor (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
automation-gateway (Red Hat package)
ansible-help
ansible
ansible-doc
ansible-test
ansible-core (Red Hat package)
uyuni-proxy-systemd-services
python3-spacewalk-client-setup
spacewalk-check
python3-spacewalk-check
spacewalk-client-tools
python3-spacewalk-client-tools
spacewalk-client-setup
automation-controller (Red Hat package)
molecule (Red Hat package)
Migration Toolkit for Containers

How to mitigate CVE-2024-8775

Install updates from vendor's website.

Ansible - addressed in versions 2.14.18, 2.15.13, 2.16.13, 2.17.6
IBM Fusion HCI - update to 2.10.0
Guardium Data Security Center (GDSC) - update to 3.8.5
IBM Security SOAR - update to 51.0.10.0
receptor (Red Hat package) - addressed in versions 1.5.1-1.el8ap, 1.5.1-1.el9ap
Migration Toolkit for Containers - update to 1.8.5
Ansible Automation Platform - addressed in versions 2.4, 2.5
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.4-8.el8ap, 2.4-8.el9ap, 2.5-5.el8ap, 2.5-5.el9ap
automation-gateway (Red Hat package) - addressed in versions 2.5.3-2.el8ap, 2.5.3-2.el9ap
ansible-help - update to 2.9.27-5
ansible - addressed in versions 2.9.27-5, 2.9.27-6
ansible-doc - update to 2.9.27-6
ansible-test - update to 2.9.27-6
ansible-test - update to 2.9.27-150000.1.20.1
ansible - update to 2.9.27-150000.1.20.1
ansible-doc - update to 2.9.27-150000.1.20.1
ansible-core (Red Hat package) - addressed in versions 2.15.13-1.el8ap, 2.15.13-1.el9ap, 2.16.13-1.el8ap, 2.16.13-1.el9ap
uyuni-proxy-systemd-services - update to 4.3.15-150000.1.30.1
python3-spacewalk-client-setup - update to 4.3.22-150000.3.100.1
spacewalk-check - update to 4.3.22-150000.3.100.1
python3-spacewalk-check - update to 4.3.22-150000.3.100.1
spacewalk-client-tools - update to 4.3.22-150000.3.100.1
python3-spacewalk-client-tools - update to 4.3.22-150000.3.100.1
spacewalk-client-setup - update to 4.3.22-150000.3.100.1
automation-controller (Red Hat package) - addressed in versions 4.5.13-1.el8ap, 4.5.13-1.el9ap
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.9
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.24, 8.7.18, 9.0.11
Oracle Solaris - update to 11.4 SRU 77
molecule (Red Hat package) - addressed in versions 24.9.0-2.el8ap, 24.9.0-2.el9ap

External References

Related Security Bulletins