All Apps and Add-ons

Rundeck App for Splunk token value exposed in log events

sylbaea
Communicator

Hello,

During troubleshooting, I noticed token value is exposed in clear text in some log events... That is not very good from a security perspective. Could you please fix that... below a sample event:

09-25-2018 04:42:08.751 +0000 ERROR ExecProcessor - message from "python <...>/splunk/etc/apps/rundeck_app/bin/rundeck.py" ERROR:Rundeck:rundeck://users : HTTP Request error: 400 Client Error: Bad Request for url: https://<FQDN>/api/18/user/list?authtoken=<MY TOKEN !>

Regards.

0 Karma
1 Solution

plambertrundeck
Engager

Version 1.0.2 of The Rundeck App for Splunk is now available in Splunkbase and addresses this issue. Thank you for your feedback!

View solution in original post

plambertrundeck
Engager

Version 1.0.2 of The Rundeck App for Splunk is now available in Splunkbase and addresses this issue. Thank you for your feedback!

plambert
Engager

Please reach out to me at plambert@rundeck.com for a patched version of the application that we expect will resolve this issue. If you're able to take the time to verify in your environment that it is resolved, then we will give you the chance to do so before publishing it.

If you don't have the time to verify, we understand, just let me know and the updated version will be published soon after.

Paul M. Lambert
Platform Solutions Architect
Rundeck, Inc

0 Karma

sylbaea
Communicator

just sent you a mail. Thanks.

0 Karma

plambert
Engager

Thank you for pointing this out. We're looking at it and will have a workaround and/or fix as soon as possible.

Paul M. Lambert
Platform Solutions Architect
Rundeck, Inc

0 Karma

plambert
Engager

If you need an immediate workaround, please comment out line 346 of $SPLUNK_HOME/etc/apps/rundeck_app/bin/rundeck.py.

We will have a new version with the correct fix (and not a workaround) released as soon as we can.

Thank you again for noticing and reporting this.

Paul M. Lambert
Platform Solutions Architect
Rundeck, Inc

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...