CVE Vulnerabilities

CVE-2023-4237

Published: Oct 04, 2023 | Modified: Dec 01, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the systems confidentiality, integrity, and availability.

Affected Software

Name Vendor Start Version End Version
Ansible_automation_platform Redhat 2.0 (including) 2.0 (including)
Ansible_collection Redhat * *

References