Description
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7155 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. |
Github GHSA |
GHSA-qv37-mfjf-42h8 | Plaintext storage of tokens in pulp_ansible |
References
History
Wed, 07 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-05-07T19:38:38.989Z
Reserved: 2022-10-21T00:00:00.000Z
Link: CVE-2022-3644
Updated: 2024-08-03T01:14:03.138Z
Status : Modified
Published: 2022-10-25T18:15:10.020
Modified: 2025-05-07T20:15:21.877
Link: CVE-2022-3644
OpenCVE Enrichment
No data.
EUVD
Github GHSA