CVE-2023-4380 is a logic flaw in Red Hat Ansible Automation Platform, Ansible Developer, Ansible Inside, and Red Hat Enterprise Linux. This vulnerability causes plaintext logging of incorrect credentials when creating private projects, leading to potential loss of confidentiality, integrity, and availability. Rated Medium (CVSS 6.3), it can be exploited remotely with low attack complexity and requires low privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.