REDHAT-BUG-2487251: Medium severity ansible/community/general vulnerability
Hi Red Hat Security Team,
I am reporting a vulnerability in community.general v13.0.0
Module: plugins/modules/keyringinfo.py
CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] with no output suppression, no nolog protection, and no documentation warning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2487251?
The severity of REDHAT-BUG-2487251 is classified as medium with a CVSS score of 5.5.
How do I fix REDHAT-BUG-2487251?
To address REDHAT-BUG-2487251, update the community.general module to the latest release that patches this vulnerability.
What are the potential impacts of REDHAT-BUG-2487251?
The potential impacts of REDHAT-BUG-2487251 include unauthorized access to sensitive passphrases stored in the OS native keyring.
In which software is REDHAT-BUG-2487251 found?
REDHAT-BUG-2487251 is found in the ansible/community.general version 13.0.0 module.
When was REDHAT-BUG-2487251 reported?
REDHAT-BUG-2487251 was reported on June 9, 2026.