Описание
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 1.6.5+dfsg-1 |
| bionic | not-affected | 1.6.5+dfsg-1 |
| cosmic | not-affected | 1.6.5+dfsg-1 |
| devel | not-affected | 1.6.5+dfsg-1 |
| disco | not-affected | 1.6.5+dfsg-1 |
| esm-apps/bionic | not-affected | 1.6.5+dfsg-1 |
| esm-apps/xenial | not-affected | 1.6.5+dfsg-1 |
| esm-infra-legacy/trusty | not-affected | 1.5.4+dfsg-1 |
| lucid | DNE | |
| precise | DNE |
Показывать по
EPSS
2.1 Low
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Ansible before 1.5.5 sets 0644 permissions for sources.list, which mig ...
Ansible sets unsafe permissions for sources.list
EPSS
2.1 Low
CVSS2
5.5 Medium
CVSS3