Loading HuntDB...

GHSA-jwcc-j78w-j73w

GitHub Security Advisory

Ansible exposes sensitive data in log files and on the terminal

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

Affected Packages

PyPI ansible
Affected versions: 2.5.0a1 (fixed in 2.5.5)
PyPI ansible
Affected versions: 2.4.0.0 (fixed in 2.4.5.0)

Related CVEs

Key Information

GHSA ID
GHSA-jwcc-j78w-j73w
Published
October 10, 2018 5:23 PM
Last Modified
November 18, 2024 4:26 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
ansible
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 16, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.