QID 995562

Date Published: 2023-10-11

QID 995562: Python (Pip) Security Update for ansible-core (GHSA-ww3m-ffrm-qvqv)

A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-ww3m-ffrm-qvqv for updates and patch information.
    Vendor References

    CVEs related to QID 995562

    Software Advisories
    Advisory ID Software Component Link