PT-2023-21844 · Unknown+1 · Ansible Semaphore+1

Published

2023-03-18

·

Updated

2025-12-15

·

CVE-2023-28609

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ansible Semaphore versions prior to 2.8.89
Description The issue is related to the mishandling of authentication in the api/auth.go file.
Recommendations For versions prior to 2.8.89, update to version 2.8.89 or later to resolve the issue.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8508
ALT-PU-2024-17909
ALT-PU-2025-15714
CVE-2023-28609
GHSA-PMHG-CMJC-3875

Affected Products

Alt Linux
Ansible Semaphore