CVE-2023-4380

medium

Description

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.

References

https://bugzilla.redhat.com/show_bug.cgi?id=2232324

https://access.redhat.com/security/cve/CVE-2023-4380

https://access.redhat.com/errata/RHSA-2023:4693

Details

Source: Mitre, NVD

Published: 2023-10-04

Updated: 2024-01-01

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium