3 ms·
I had thought of the shell module. But the attacker would still have to know your playbook is using that module, and they'd have to know the variables you are p
by jerrac 9y ago
I had thought of the shell module. But the attacker would still have to know your playbook is using that module, and they'd have to know the variables you are passing into that module in order to override them.
So, can you explain how an attacker would figure that information out? Assuming the playbooks are stored in source control like the Tower docs recommend, and all your variable values are mostly in source control as well.