Skip to content
XEIZE
DocsIntegrations

Get started

  • Overview

Security tools

  • SAST
  • SCA

Integrations

Reference

    • Overview
      • Overview
        • Overview
          • Overview
          • Sensitive data exposure in Ansible default logging settings
          • Ansible enables the legacy allow_unsafe_lookups option
          • Ansible Galaxy server uses HTTP
          • Review Ansible’s default user-switching settings
  • Glossary

Advanced usage

  • CLI
/Vulnerability documentation/IaC/Ansible/Configuration

Configuration

Guidance on communication, logging, and privileges in Ansible defaults.

Documentation

Article Path
Sensitive data exposure in Ansible default logging settings ansible/config/logging_of_sensitive_data_in_defaults
Ansible enables the legacy allow_unsafe_lookups option ansible/config/allow_unsafe_lookups_enabled_in_defaults
Ansible Galaxy server uses HTTP ansible/config/communication_over_http_in_defaults
Review Ansible’s default user-switching settings ansible/config/privilege_escalation_using_become_plugin_in_defaults

Related pages4

Sensitive data exposure in Ansible default logging settings

Apply no_log to sensitive task output, and protect debugging output and log stores separately.

Ansible enables the legacy allow_unsafe_lookups option

On older Ansible versions, enabling allow_unsafe_lookups can allow external data to be evaluated again as a template. Review how lookup results are used and trusted in the version you run.

Ansible Galaxy server uses HTTP

Use HTTPS and certificate verification for Galaxy server connections.

Review Ansible’s default user-switching settings

Enable user switching only where required and verify the execution account.

PreviousPostgreSQL duration logging needs review
NextSensitive data exposure in Ansible default logging settings
XEIZE DocumentationTechnical support
On this page
Documentation