VulnerabilityModified
CVE-2023-4237
This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
HIGH 7.8EPSS 0.25%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-497
- Affected
- redhat/ansible automation platform · redhat/ansible collection
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHBA-2023:5653
- https://access.redhat.com/errata/RHBA-2023:5666
- https://access.redhat.com/security/cve/CVE-2023-4237Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2229979Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHBA-2023:5653
- https://access.redhat.com/errata/RHBA-2023:5666
- https://access.redhat.com/security/cve/CVE-2023-4237Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2229979Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20241025-0002/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.