CVE-2023-4380
Platform: token exposed at importing project
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
Red Hat · Red Hat Ansible Automation Platform 2.4 for RHEL 8Red Hat · Red Hat Ansible Automation Platform 2.4 for RHEL 9Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →