CVE-2023-4237: Platform: ec2_key module prints out the private key directly to the standard output
"When creating a new keypair the ec2key module prints out the private key directly to the standard output. I wasn't able to find any way to disable this behavior in the module's documentation. This makes it unusable in any kind of public CI workflow such as GHA."
Confirmed impacting all collection releases, and back to ansible-core 2.8 (did not test further back).
Other sources
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4237?
CVE-2023-4237 is a vulnerability found in the Ansible Automation Platform that allows an attacker to fetch private keys from log files, compromising the system's confidentiality, integrity, and availability.
How does CVE-2023-4237 affect Redhat Ansible Automation Platform?
CVE-2023-4237 affects Redhat Ansible Automation Platform version 2.0.
How does CVE-2023-4237 affect Redhat Ansible Collection?
CVE-2023-4237 affects Redhat Ansible Collection.
How does CVE-2023-4237 affect pip/ansible-core?
CVE-2023-4237 affects pip/ansible-core versions 2.8.0 to 2.15.2.
What is the severity of CVE-2023-4237?
CVE-2023-4237 has a severity score of 7.8 (high).
How can I fix CVE-2023-4237?
To fix CVE-2023-4237, update to a patched version of the affected software.