7.8
CVSSv3

CVE-2023-4237

Published: 04/10/2023 Updated: 01/12/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an malicious user to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible automation platform 2.0

redhat ansible collection

Vendor Advisories

Debian Bug report logs - #1055300 ansible: CVE-2023-4237 Package: src:ansible; Maintainer for src:ansible is Lee Garrett <debian@rocketjumpeu>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 3 Nov 2023 19:24:06 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug Toggl ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...