6.3

CVE-2023-4380

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.

Data is provided by the National Vulnerability Database (NVD)
RedhatAnsible Automation Platform Version2.4
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
RedhatAnsible Developer Version1.1
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
RedhatAnsible Inside Version1.2
   RedhatEnterprise Linux Version8.0
   RedhatEnterprise Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.234
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
secalert@redhat.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.