PT-2020-7682 · Ansible+1 · Ansible+2

Published

2014-04-22

·

Updated

2022-05-17

·

CVE-2014-4658

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 1.5.5
Description The issue concerns the vault subsystem in Ansible, where it fails to set the umask before creating or modifying a vault file. This oversight allows local users to access sensitive key information by reading the file.
Recommendations For versions prior to 1.5.5, update to version 1.5.5 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1523
CVE-2014-4658
GHSA-5G4V-2PC6-4HH4
PYSEC-2020-200

Affected Products

Alt Linux
Ansible
Ansible-Core