VulnerabilityModified
CVE-2014-4659
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
MEDIUM 5.5EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- redhat/ansible
- Source
- cve@mitre.org
References
- https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdRelease Notes
- https://www.securityfocus.com/bid/68234Third Party Advisory, VDB Entry
- https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdRelease Notes
- https://www.securityfocus.com/bid/68234Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.