Plaintext storage of tokens in pulp_ansible
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
02 / AFFECTED SOFTWARE
Affected packages
74 explicit affected versions
74 explicit affected versions
2 explicit affected versions
04 / EVIDENCE
Source records
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3644.json
- https://github.com/pulp/pulp_ansible/blob/main/pulp_ansible/app/models.py#L234
- https://nvd.nist.gov/vuln/detail/CVE-2022-3644
- https://github.com/advisories/GHSA-qv37-mfjf-42h8
- https://github.com/pulp/pulp_ansible
- https://github.com/pulp/pulp_ansible/commit/d13c427b09482a7f598d8ee597d17a8a34888665
- https://github.com/pulp/pulp_ansible/issues/1221
- https://pypi.org/project/pulp-ansible