Source: ansible X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for ansible. CVE-2026-80158[0]: | A flaw was found in the ipa_getkeytab module of the | community.general Ansible collection. The module's bind_pw | parameter, used to supply the LDAP simple-bind password when | retrieving a Kerberos keytab, is not declared with no_log, unlike | the sibling password parameter in the same module. As a consequence, | the supplied IPA/LDAP bind password is recorded in cleartext in the | managed host's system journal/syslog (the module's "Invoked with" | record), is included in the module's return values and verbose (-v) | output, and is displayed in Automation Controller / AWX job output. | The password is additionally passed on the command line to the ipa- | getkeytab helper (as --bindpw <value>), exposing it in the process | list to local users while the command runs. An attacker able to read | these logs, job output, or the process table can obtain the | directory bind credential, potentially compromising the accounts and | objects that credential can access. https://bugzilla.redhat.com/show_bug.cgi?id=2524651 If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-80158 https://www.cve.org/CVERecord?id=CVE-2026-80158 Please adjust the affected versions in the BTS as needed.

