CVE-2022-3644
published 2022-10-25CVE-2022-3644: The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API ()…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.28%
19.6th percentile
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ansible_automation_platform | — | — |
| redhat | satellite | — | — |
| redhat | update_infrastructure | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Pulp: Tokens stored in plaintext
vendor_redhat·2022-10-04·CVSS 5.5
CVE-2022-3644 [MEDIUM] CWE-256 Pulp: Tokens stored in plaintext
Pulp: Tokens stored in plaintext
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
A flaw exists in the collection remote for pulp_ansible, where tokens are stored in plaintext instead of using pulp's encrypted field. This flaw allows an attacker with sufficient privileges to read the stored tokens, resulting in the loss of confidentiality.
Package: python-pulp-ansible (Red Hat Ansible Automation Platform 2) - Will not fix
Package: pulp (Red Hat Update Infrastructure 3 for Cloud Providers) - Affected
OSV
Plaintext storage of tokens in pulp_ansible
osv·2022-10-25
CVE-2022-3644 [MEDIUM] Plaintext storage of tokens in pulp_ansible
Plaintext storage of tokens in pulp_ansible
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
GHSA
Plaintext storage of tokens in pulp_ansible
ghsa·2022-10-25
CVE-2022-3644 [MEDIUM] CWE-256 Plaintext storage of tokens in pulp_ansible
Plaintext storage of tokens in pulp_ansible
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
No detection rules found.
No public exploits indexed.
2022-10-25
Published