Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3644

Опубликовано: 04 окт. 2022
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

A flaw exists in the collection remote for pulp_ansible, where tokens are stored in plaintext instead of using pulp's encrypted field. This flaw allows an attacker with sufficient privileges to read the stored tokens, resulting in the loss of confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python-pulp-ansibleWill not fix
Red Hat Update Infrastructure 3 for Cloud ProviderspulpAffected
Red Hat Satellite 6.14 for RHEL 8python-pulp-ansibleFixedRHSA-2023:681808.11.2023
Red Hat Satellite 6.14 for RHEL 8python-pulp-ansibleFixedRHSA-2023:681808.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-256

EPSS

Процентиль: 20%
0.00281
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 4 года назад

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

CVSS3: 5.5
redos
около 1 месяца назад

Уязвимость python-pulp-ansible

CVSS3: 5.5
github
почти 4 года назад

Plaintext storage of tokens in pulp_ansible

EPSS

Процентиль: 20%
0.00281
Низкий

4.1 Medium

CVSS3