← Späť na vyhľadávanie CVE

CVE-2026-11820

Ansible

Popis

Module: plugins/modules/nexmo.py CVSS 3.1: 6.5 MEDIUM — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: api_key and api_secret are declared no_log=True at the input level, but both credentials are immediately URL-encoded into a GET request as query parameters, bypassing all no_log protection. Vulnerable Code (lines 82-93): msg = { -api_key-: module.params.get(-api_key-), -api_secret-: module.params.get(-api_secret-), -from-: module.params.get(-src-), -text-: module.params.get(-msg-), } url = f-{NEXMO_API}?{urlencode(msg)}- response, info = fetch_url(module, url, headers=headers) Observed Output: https://rest.nexmo.com/sms/json?api_key=a1b2c3d4&api_secret=MyS3cr3tK3y!!&from=AnsibleBot&to=15551234567&text=Hello Exposure Vectors: Ansible verbose output (-vvv) logs the full request URL Vonage/Nexmo server access logs record credentials in query string HTTP proxies, SIEM, and network inspection tools capture the full URL AWX/Automation Controller network debug logs Fix: Switch to POST with credentials in the request body: data = urlencode({-api_key-: api_key, -api_secret-: api_secret, -from-: src, -to-: number, -text-: msg}) fetch_url(module, NEXMO_API, data=data, method=-POST-, headers={-Content-Type-: -application/x-www-form-urlencoded-})

CVSS 6.5EPSS 0.28700000000000003%Riziko 0.67
Zobraziť zdroj
Zverejnené
2026-06-23 21:16:54
Dotknuté verzie
unknown
Typ
Kritický softvér
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Operačné systémy
Linux