Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv37-mfjf-42h8

Опубликовано: 25 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Plaintext storage of tokens in pulp_ansible

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

Пакеты

Наименование

pulp-ansible

pip
Затронутые версииВерсия исправления

< 0.15.0

0.15.0

EPSS

Процентиль: 20%
0.00279
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-256
CWE-522

Связанные уязвимости

CVSS3: 4.1
redhat
почти 4 года назад

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

CVSS3: 5.5
nvd
почти 4 года назад

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

CVSS3: 5.5
redos
около 1 месяца назад

Уязвимость python-pulp-ansible

EPSS

Процентиль: 20%
0.00279
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-256
CWE-522