Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qv37-mfjf-42h8: Plaintext storage of tokens in pulp_ansible

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp’s encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

ghsa
#git

Plaintext storage of tokens in pulp_ansible

Moderate severity GitHub Reviewed Published Oct 25, 2022 • Updated Oct 25, 2022

Related news

CVE-2022-3644: pulp_ansible/models.py at main · pulp/pulp_ansible

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.