Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4659

Опубликовано: 20 фев. 2020
Источник: debian

Описание

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed1.5.5+dfsg-1package

Примечания

  • https://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 6 лет назад

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

CVSS3: 5.5
redhat
больше 11 лет назад

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

CVSS3: 5.5
nvd
почти 6 лет назад

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

CVSS3: 5.5
github
больше 3 лет назад

Ansible sets unsafe permissions for sources.list