PT-2020-7683 · Ansible+1 · Ansible+2

Published

2014-04-22

·

Updated

2022-05-17

·

CVE-2014-4659

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ansible versions prior to 1.5.5
Description The issue allows local users to potentially obtain sensitive credential information by reading a file that uses the "deb http://user:pass@server:port/" format, due to the incorrect permissions set for sources.list.
Recommendations For Ansible versions prior to 1.5.5, update to version 1.5.5 or later to resolve the issue. As a temporary workaround, consider changing the permissions of the sources.list file to prevent unauthorized access. Restrict access to sensitive credential information stored in the sources.list file until the issue is resolved.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1523
CVE-2014-4659
GHSA-6667-F46P-PG88
PYSEC-2020-201

Affected Products

Alt Linux
Ansible
Ansible-Core