cbcvebase.
CVE-2023-4237
published 2023-10-04

CVE-2023-4237: A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianansible< ansible 7.7.0+dfsg-3+deb12u1 (bookworm)ansible 7.7.0+dfsg-3+deb12u1 (bookworm)
redhatansible>= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u12.10.7+merged+base+2.10.17+dfsg-0+deb11u1
redhatansible>= 0 < 7.7.0+dfsg-3+deb12u17.7.0+dfsg-3+deb12u1
redhatansible>= 0 < 9.4.0+dfsg-19.4.0+dfsg-1
redhatansible>= 0 < 9.4.0+dfsg-19.4.0+dfsg-1
redhatansible_automation_platform

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.