Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-0013 Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the \"deb http://user:pass@server:port/\" format.
Github GHSA Github GHSA GHSA-6667-f46p-pg88 Ansible sets unsafe permissions for sources.list
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T11:20:26.680Z

Reserved: 2014-06-25T00:00:00

Link: CVE-2014-4659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-20T15:15:11.680

Modified: 2024-11-21T02:10:39.807

Link: CVE-2014-4659

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-06-26T00:00:00Z

Links: CVE-2014-4659 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses