Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4660

Опубликовано: 20 фев. 2020
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
Версия до 1.5.5 (исключая)

EPSS

Процентиль: 31%
0.00119
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 6 лет назад

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.

CVSS3: 5.5
debian
почти 6 лет назад

Ansible before 1.5.5 constructs filenames containing user and password ...

CVSS3: 5.5
github
больше 3 лет назад

Ansible discloses credential information

EPSS

Процентиль: 31%
0.00119
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-522