All Apps and Add-ons

Rundeck App for Splunk token value exposed in log events

sylbaea
Communicator

Hello,

During troubleshooting, I noticed token value is exposed in clear text in some log events... That is not very good from a security perspective. Could you please fix that... below a sample event:

09-25-2018 04:42:08.751 +0000 ERROR ExecProcessor - message from "python <...>/splunk/etc/apps/rundeck_app/bin/rundeck.py" ERROR:Rundeck:rundeck://users : HTTP Request error: 400 Client Error: Bad Request for url: https://<FQDN>/api/18/user/list?authtoken=<MY TOKEN !>

Regards.

0 Karma
1 Solution

plambertrundeck
Engager

Version 1.0.2 of The Rundeck App for Splunk is now available in Splunkbase and addresses this issue. Thank you for your feedback!

View solution in original post

plambertrundeck
Engager

Version 1.0.2 of The Rundeck App for Splunk is now available in Splunkbase and addresses this issue. Thank you for your feedback!

plambert
Engager

Please reach out to me at plambert@rundeck.com for a patched version of the application that we expect will resolve this issue. If you're able to take the time to verify in your environment that it is resolved, then we will give you the chance to do so before publishing it.

If you don't have the time to verify, we understand, just let me know and the updated version will be published soon after.

Paul M. Lambert
Platform Solutions Architect
Rundeck, Inc

0 Karma

sylbaea
Communicator

just sent you a mail. Thanks.

0 Karma

plambert
Engager

Thank you for pointing this out. We're looking at it and will have a workaround and/or fix as soon as possible.

Paul M. Lambert
Platform Solutions Architect
Rundeck, Inc

0 Karma

plambert
Engager

If you need an immediate workaround, please comment out line 346 of $SPLUNK_HOME/etc/apps/rundeck_app/bin/rundeck.py.

We will have a new version with the correct fix (and not a workaround) released as soon as we can.

Thank you again for noticing and reporting this.

Paul M. Lambert
Platform Solutions Architect
Rundeck, Inc

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...