Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security scanners flag tests/integration/targets/win_psmodule_info/files/ansiblevault.0.3.0.nupkg #549

Open
felixfontein opened this issue Jan 11, 2024 · 0 comments

Comments

@felixfontein
Copy link
Contributor

SUMMARY

Ref: https://forum.ansible.com/t/ansible-vault-0-3-0-vulnerability/3256/2

The file was added in #62 as part of the win_psmodule_info integration test suite. I don't think this is a security problem, since that program which has the vulnerabilities is not used (and thus the vulnerabilities have no affect), but it will be flagged by some security scanners when looking at the collection (when installed via ansible-galaxy collection install, for example in EEs), or when scanning the Ansible community package source distribution.

It's probably a good idea to upgrade that program, or replace it by something even more harmless.

ISSUE TYPE
  • Bug Report
COMPONENT NAME

win_psmodule_info integration tests

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant