CVE-2023-4380

CVSS V2 None CVSS V3 None
Description
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
Overview
  • CVE ID
  • CVE-2023-4380
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-04T14:24:35.121Z
  • Last Modified Date
  • 2024-05-01T20:21:11.534Z
References
Reference URL Reference Tags
https://access.redhat.com/errata/RHSA-2023:4693 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/security/cve/CVE-2023-4380 vdb-entry x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=2232324 issue-tracking x_refsource_REDHAT
History
Created Old Value New Value Data Type Notes
2024-06-24 19:08:48 Added to TrackCVE