FlawAtlas
Search the atlas
CVE-2022-3644 Moderate

Plaintext storage of tokens in pulp_ansible

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

Exploit probability 0.3%
Published July 7, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI pulp-ansible

74 explicit affected versions

PyPI pulp-ansible

74 explicit affected versions

Unknown Unknown

2 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2022-3644

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

View original source
Open Source Vulnerabilities PYSEC-2026-900

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

View original source
Open Source Vulnerabilities GHSA-qv37-mfjf-42h8

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

View original source

05 / REFERENCES

Further evidence