CyberRota Analysis
AI-GeneratedA vulnerability exists in ansible-collection-redhat-leapp that affects the handling of PostgreSQL data backups when executed with elevated privileges. The flaw results in the creation of a backup archive with insecure permissions, allowing local non-root users on the managed node to access sensitive data, which can lead to information disclosure. Organizations utilizing this Ansible collection, particularly those managing PostgreSQL databases, should prioritize remediation efforts to mitigate potential data exposure risks.
Original NVD Description
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure.