CVE-2023-4237
published 2023-10-04CVE-2023-4237: A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.1th percentile
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 7.7.0+dfsg-3+deb12u1 (bookworm) | ansible 7.7.0+dfsg-3+deb12u1 (bookworm) |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 |
| redhat | ansible | >= 0 < 7.7.0+dfsg-3+deb12u1 | 7.7.0+dfsg-3+deb12u1 |
| redhat | ansible | >= 0 < 9.4.0+dfsg-1 | 9.4.0+dfsg-1 |
| redhat | ansible | >= 0 < 9.4.0+dfsg-1 | 9.4.0+dfsg-1 |
| redhat | ansible_automation_platform | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-4237: A flaw was found in the Ansible Automation Platform
osv·2023-10-04·CVSS 7.8
CVE-2023-4237 [HIGH] CVE-2023-4237: A flaw was found in the Ansible Automation Platform
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
OSV
Ansible may expose private key
osv·2023-10-04
CVE-2023-4237 [MEDIUM] Ansible may expose private key
Ansible may expose private key
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
GHSA
Ansible may expose private key
ghsa·2023-10-04
CVE-2023-4237 [MEDIUM] CWE-497 Ansible may expose private key
Ansible may expose private key
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
Red Hat
platform: ec2_key module prints out the private key directly to the standard output
vendor_redhat·2023-08-08·CVSS 7.3
CVE-2023-4237 [HIGH] CWE-497 platform: ec2_key module prints out the private key directly to the standard output
platform: ec2_key module prints out the private key directly to the standard output
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
Debian
CVE-2023-4237: ansible - A flaw was found in the Ansible Automation Platform. When creating a new keypair...
vendor_debian·2023·CVSS 7.3
CVE-2023-4237 [HIGH] CVE-2023-4237: ansible - A flaw was found in the Ansible Automation Platform. When creating a new keypair...
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.
Scope: local
bookworm: resolved (fixed in 7.7.0+dfsg-3+deb12u1)
bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1)
forky: resolved (fixed in 9.4.0+dfsg-1)
sid: resolved (fixed in 9.4.0+dfsg-1)
trixie: resolved (fixed in 9.4.0+dfsg-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHBA-2023:5653https://access.redhat.com/errata/RHBA-2023:5666https://access.redhat.com/security/cve/CVE-2023-4237https://bugzilla.redhat.com/show_bug.cgi?id=2229979https://access.redhat.com/errata/RHBA-2023:5653https://access.redhat.com/errata/RHBA-2023:5666https://access.redhat.com/security/cve/CVE-2023-4237https://bugzilla.redhat.com/show_bug.cgi?id=2229979https://security.netapp.com/advisory/ntap-20241025-0002/
2023-10-04
Published