Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4380
HistoryOct 04, 2023 - 12:00 a.m.

CVE-2023-4380

2023-10-0400:00:00
ubuntu.com
ubuntu.com
8
ansible automation platform
logic flaw
plaintext credentials
confidentiality
integrity
availability

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

27.7%

A logic flaw exists in Ansible Automation platform. Whenever a private
project is created with incorrect credentials, they are logged in
plaintext. This flaw allows an attacker to retrieve the credentials from
the log, resulting in the loss of confidentiality, integrity, and
availability.

Notes

Author Note
sbeattie core ansible binaries were split into ansible-base, which got renamed to ansible-core

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

27.7%