mirror of
https://github.com/ansible-collections/community.general.git
synced 2026-02-04 07:51:50 +00:00
keycloak_user: mark credentials[].value as no_log=True (#11005)
Mark credentials[].value as no_log=True.
This commit is contained in:
parent
ce0d06b306
commit
54af64ad36
2 changed files with 5 additions and 1 deletions
4
changelogs/fragments/11005-keycloak_user.yml
Normal file
4
changelogs/fragments/11005-keycloak_user.yml
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
security_fixes:
|
||||
- "keycloak_user - the parameter ``credentials[].value`` is now marked as ``no_log=true``. Before it was logged by Ansible, unless the task was marked as ``no_log: true``.
|
||||
Since this parameter can be used for passwords, this resulted in credential leaking
|
||||
(https://github.com/ansible-collections/community.general/issues/11000, https://github.com/ansible-collections/community.general/pull/11005)."
|
||||
Loading…
Add table
Add a link
Reference in a new issue