Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4660

Опубликовано: 20 фев. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 2.1
CVSS3: 5.5

Описание

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.

РелизСтатусПримечание
artful

not-affected

1.6.5+dfsg-1
bionic

not-affected

1.6.5+dfsg-1
cosmic

not-affected

1.6.5+dfsg-1
devel

not-affected

1.6.5+dfsg-1
disco

not-affected

1.6.5+dfsg-1
eoan

not-affected

1.6.5+dfsg-1
esm-apps/bionic

not-affected

1.6.5+dfsg-1
esm-apps/focal

not-affected

1.6.5+dfsg-1
esm-apps/jammy

not-affected

1.6.5+dfsg-1
esm-apps/xenial

not-affected

1.6.5+dfsg-1

Показывать по

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 6 лет назад

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.

CVSS3: 5.5
debian
почти 6 лет назад

Ansible before 1.5.5 constructs filenames containing user and password ...

CVSS3: 5.5
github
больше 3 лет назад

Ansible discloses credential information

2.1 Low

CVSS2

5.5 Medium

CVSS3