← Back

CVE-2023-4380

nvd nist
Published: Oct 4, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: NVD

Description

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.

Affected (3)

3 products
Ansible Automation Platform
Ansible Developer
Ansible Inside
Configuration A
3 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 2.4
Version 1.1
Version 1.2
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0
Redhat
Enterprise Linux
Version 9.0

References (6)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.