Description
A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | =10.0.0+dfsg-1 || =10.0.1+dfsg-1 || =10.1.0+dfsg-1 || =10.5.0+dfsg-1 || =10.5.0+dfsg-2 || =10.6.0+dfsg-1 || =11.1.0+dfsg-1 || =11.2.0+dfsg-1 || =12.0.0+dfsg-1 || =12.0.0~a1+dfsg-1 || =12.0.0~a2+dfsg-1 || =12.0.0~a4+dfsg-1 || =12.0.0~a6+dfsg-1 || =12.0.0~b1+dfsg-1 || =12.0.0~b2+dfsg-1 || =12.0.0~b3+dfsg-1 || =12.0.0~b5+dfsg-1 || =12.2.0+dfsg-1 || =13.1.0+dfsg-1 || =13.4.0+dfsg-1 || =14.0.0+dfsg-1 || =14.0.0~a4+dfsg-1 || =7.3.0+dfsg-1 || =7.7.0+dfsg-1 || =7.7.0+dfsg-2 || =7.7.0+dfsg-3 || =7.7.0+dfsg-3+deb12u1 || =9.4.0+dfsg-1 || =9.5.1+dfsg-1 |
 debian 13 | | =12.0.0+dfsg-0+deb13u1 || =12.0.0+dfsg-1 || =12.0.0~a6+dfsg-1 || =12.0.0~b1+dfsg-1 || =12.0.0~b2+dfsg-1 || =12.0.0~b3+dfsg-1 || =12.0.0~b5+dfsg-0+deb13u1 || =12.0.0~b5+dfsg-1 || =12.2.0+dfsg-1 || =13.1.0+dfsg-1 || =13.4.0+dfsg-1 || =14.0.0+dfsg-1 || =14.0.0~a4+dfsg-1 |
 debian 14 | | =12.0.0+dfsg-1 || =12.0.0~a6+dfsg-1 || =12.0.0~b1+dfsg-1 || =12.0.0~b2+dfsg-1 || =12.0.0~b3+dfsg-1 || =12.0.0~b5+dfsg-1 || =12.2.0+dfsg-1 || =13.1.0+dfsg-1 || =13.4.0+dfsg-1 || =14.0.0+dfsg-1 || =14.0.0~a4+dfsg-1 |