A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, resulting in the loss of confidentiality, integrity, and availability.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2023:4693 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2023-4380 | vdb entry vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2232324 | vendor advisory issue tracking |