Lucene search

K
cveRedhatCVE-2022-3644
HistoryOct 25, 2022 - 6:15 p.m.

CVE-2022-3644

2022-10-2518:15:10
CWE-256
CWE-522
redhat
web.nvd.nist.gov
55
6
pulp ansible
cve-2022-3644
plaintext
token
storage
api
security vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

17.8%

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp’s encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

Affected configurations

Nvd
Vulners
Node
pulpprojectpulp_ansibleMatch-
Node
redhatansible_automation_platformMatch2.0
OR
redhatsatelliteMatch6.0
OR
redhatupdate_infrastructureMatch3.0
VendorProductVersionCPE
pulpprojectpulp_ansible-cpe:2.3:a:pulpproject:pulp_ansible:-:*:*:*:*:*:*:*
redhatansible_automation_platform2.0cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*
redhatsatellite6.0cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
redhatupdate_infrastructure3.0cpe:2.3:a:redhat:update_infrastructure:3.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "pulp_ansible",
    "versions": [
      {
        "version": "0.15",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

17.8%