Description
Requests to an http:// URL through ansible.builtin.uri are not encrypted in transit.
Potential impact
An actor able to intercept the connection can read or alter tokens, cookies, or data in requests and responses.
Remediation
Configure HTTPS on the target and change the URL to https://. Keep certificate verification enabled. For HTTP-only targets, limit use and avoid sending sensitive data.
Examples
The examples move the same status request to HTTPS. The server must support HTTPS and provide a trusted certificate.
Before
yaml
- name: Check site status
hosts: localhost
tasks:
- name: Request site over HTTP
ansible.builtin.uri:
url: "http://www.example.com"
method: GET
register: site_response
After
yaml
- name: Check site status
hosts: localhost
tasks:
- name: Request site over HTTPS
ansible.builtin.uri:
url: "https://www.example.com"
method: GET
register: site_response