CyberRota Analysis
AI-GeneratedThe ipa_getkeytab module in the community.general Ansible collection is vulnerable due to the bind_pw parameter not being properly secured, leading to the LDAP simple-bind password being logged in cleartext in system journals and displayed in job outputs. This exposure allows local users to access sensitive credentials, potentially compromising accounts and objects associated with the bind password. Organizations using this Ansible module, especially those managing sensitive directory services, should prioritize addressing this vulnerability to mitigate the risk of credential theft.
Original NVD Description
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.