6.3

CVE-2023-4380

Platform: token exposed at importing project

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Ansible Automation Platform Version 2.4
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Ansible Developer Version 1.1
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Ansible Inside Version 1.2
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.475
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
RedHat 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://access.redhat.com/errata/RHSA-2023:4693
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-4380
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2232324
Vendor Advisory
Issue Tracking