CVE-2023-4380: Platform: token exposed at importing project
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
Other sources
A logic flaw exists in Ansible. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4380?
CVE-2023-4380 is a logic flaw vulnerability in Ansible that allows an attacker to retrieve credentials from the log.
How does CVE-2023-4380 affect the affected software?
CVE-2023-4380 affects the affected software by logging credentials in plaintext, leading to the loss of confidentiality, integrity, and availability.
What is the severity of CVE-2023-4380?
The severity of CVE-2023-4380 is medium with a severity value of 6.3.
How can I fix CVE-2023-4380?
To fix CVE-2023-4380, update to version 1.0.1 of the 'automation-eda-controller' package or update to the latest version of the affected software.
What is the Common Weakness Enumeration (CWE) of CVE-2023-4380?
The Common Weakness Enumeration (CWE) of CVE-2023-4380 is CWE-532.