Headline
GHSA-qv37-mfjf-42h8: Plaintext storage of tokens in pulp_ansible
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp’s encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
Plaintext storage of tokens in pulp_ansible
Moderate severity GitHub Reviewed Published Oct 25, 2022 • Updated Oct 25, 2022
Related news
CVE-2022-3644: pulp_ansible/models.py at main · pulp/pulp_ansible
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.