Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4658

Опубликовано: 20 фев. 2020
Источник: debian

Описание

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed1.5.5+dfsg-1package

Примечания

  • https://github.com/ansible/ansible/commit/a0e027fe362fbc209dbeff2f72d6e95f39885c69

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 6 лет назад

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

CVSS3: 5.5
redhat
почти 12 лет назад

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

CVSS3: 5.5
nvd
почти 6 лет назад

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

CVSS3: 5.5
github
больше 3 лет назад

Ansible Sensitive Files Are Locally Readable