You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
ansible/test
Sloane Hertel edd1e1723c
[2.7] CVE-2020-1746 - Remove the params module option from ldap_attr and ldap_entry (#68716)
* Remove the params module option from ldap_attr and ldap_entry

Module options that circumvent Ansible's option handling were disallowed
in:
https://meetbot.fedoraproject.org/ansible-meeting/2017-09-28/ansible_dev_meeting.2017-09-28-15.00.log.html

Additionally, this particular usage can be insecure if bind_pw is set
this way as the password could end up in a logfile or displayed on
stdout.

Fixes CVE-2020-1746

(cherry picked from commit 0ff609f1bc)

* Fix formatting for option names

Co-Authored-By: Felix Fontein <felix@fontein.de>

* Fix fail_json

* update sanity

* fix indentation error

Co-authored-by: Toshio Kuratomi <a.badger@gmail.com>
Co-authored-by: Felix Fontein <felix@fontein.de>
6 years ago
..
cache
env [stable-2.7] Add `env` command to ansible-test and run in CI. (#50176) 7 years ago
integration prevent ansible_facts injection (#68431) (#68446) 6 years ago
legacy safe_eval fix (#57188) 7 years ago
results
runner [stable-2.7] Update tests to use RHEL 7.8. (#68787) 6 years ago
sanity [2.7] CVE-2020-1746 - Remove the params module option from ldap_attr and ldap_entry (#68716) 6 years ago
units [stable-2.7] Wrap CLI passwords as AnsibleUnsafeText (#63352) (#63392) 6 years ago
utils Fix pylint issue. 6 years ago