CVE-2014-4660
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a…
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- redhat/ansible
- Source
- cve@mitre.org
References
- https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdRelease Notes
- https://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08Patch
- https://security-tracker.debian.org/tracker/CVE-2014-4660Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/06/26/19Mailing List, Patch, Third Party Advisory
- https://www.securityfocus.com/bid/68231Third Party Advisory, VDB Entry
- https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdRelease Notes
- https://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08Patch
- https://security-tracker.debian.org/tracker/CVE-2014-4660Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2014/06/26/19Mailing List, Patch, Third Party Advisory
- https://www.securityfocus.com/bid/68231Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.