A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version. Once published, anyone who downloads or installs the collection can view the secrets.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-26971 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version. Once published, anyone who downloads or installs the collection can view the secrets.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-03T17:01:07.697Z

Reserved: 2021-08-03T00:00:00

Link: CVE-2021-3681

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-18T17:15:15.507

Modified: 2024-11-21T06:22:08.930

Link: CVE-2021-3681

cve-icon Redhat

Severity : Important

Publid Date: 2021-08-04T07:00:00Z

Links: CVE-2021-3681 - Bugzilla

cve-icon OpenCVE Enrichment

No data.