The collection remote for pulp_ansible stores tokens in plaintext instead of using pulps encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
Storing a password in plaintext may result in a system compromise.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pulp_ansible | Pulpproject | - (including) | - (including) |
Red Hat Satellite 6.14 for RHEL 8 | RedHat | python-pulp-ansible-1:0.16.0-1.el8pc | * |
Red Hat Satellite 6.14 for RHEL 8 | RedHat | python-pulp-ansible-1:0.16.0-1.el8pc | * |