Описание
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
A flaw exists in the collection remote for pulp_ansible, where tokens are stored in plaintext instead of using pulp's encrypted field. This flaw allows an attacker with sufficient privileges to read the stored tokens, resulting in the loss of confidentiality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | python-pulp-ansible | Will not fix | ||
| Red Hat Update Infrastructure 3 for Cloud Providers | pulp | Affected | ||
| Red Hat Satellite 6.14 for RHEL 8 | python-pulp-ansible | Fixed | RHSA-2023:6818 | 08.11.2023 |
| Red Hat Satellite 6.14 for RHEL 8 | python-pulp-ansible | Fixed | RHSA-2023:6818 | 08.11.2023 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-256
https://bugzilla.redhat.com/show_bug.cgi?id=2131990Pulp: Tokens stored in plaintext
EPSS
Процентиль: 20%
0.00281
Низкий
4.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
nvd
почти 4 года назад
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
EPSS
Процентиль: 20%
0.00281
Низкий
4.1 Medium
CVSS3