PT-2026-82340 · Ansible · Community.General
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
community.general Ansible collection (affected versions not specified)
Description
A flaw exists in the
ipa getkeytab module where the bind pw parameter, used for LDAP simple-bind passwords during Kerberos keytab retrieval, lacks the no log declaration. This causes the password to be recorded in cleartext within the managed host's system journal or syslog, included in return values and verbose output, and displayed in Automation Controller or AWX job outputs. Additionally, the password is passed via the command line to the ipa-getkeytab helper using the --bindpw flag, making it visible in the process list to local users during execution. An attacker with access to these logs, outputs, or the process table could obtain the directory bind credential and compromise accessible accounts and objects.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, avoid using the
bind pw parameter in the ipa getkeytab module until a patch is available. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Community.General