Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgmq-rhmw-xw3r

Опубликовано: 31 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

EPSS

Процентиль: 2%
0.00016
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 4.4
redhat
2 месяца назад

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

CVSS3: 4.4
nvd
около 2 месяцев назад

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

CVSS3: 4.4
fstec
2 месяца назад

Уязвимость интерфейса Gateway API платформы автоматизации Red Hat Ansible Automation Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00016
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-312