Lucene search

K
nvd[email protected]NVD:CVE-2023-4380
HistoryOct 04, 2023 - 3:15 p.m.

CVE-2023-4380

2023-10-0415:15:12
CWE-532
web.nvd.nist.gov
6
cve-2023-4380
ansible
logic flaw
private project
credentials
plaintext
attacker
confidentiality
integrity
availability

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

27.7%

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.

Affected configurations

Nvd
Node
redhatansible_automation_platformMatch2.4
OR
redhatansible_developerMatch1.1
OR
redhatansible_insideMatch1.2
AND
redhatenterprise_linuxMatch8.0
OR
redhatenterprise_linuxMatch9.0
VendorProductVersionCPE
redhatansible_automation_platform2.4cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
redhatansible_developer1.1cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
redhatansible_inside1.2cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
redhatenterprise_linux8.0cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
redhatenterprise_linux9.0cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

27.7%