Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4658

Опубликовано: 20 фев. 2020
Источник: debian
EPSS Низкий

Описание

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed1.5.5+dfsg-1package

Примечания

  • https://github.com/ansible/ansible/commit/a0e027fe362fbc209dbeff2f72d6e95f39885c69

EPSS

Процентиль: 35%
0.00418
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

CVSS3: 5.5
redhat
больше 12 лет назад

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

CVSS3: 5.5
nvd
больше 6 лет назад

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

CVSS3: 5.5
github
около 4 лет назад

Ansible Sensitive Files Are Locally Readable

EPSS

Процентиль: 35%
0.00418
Низкий