CVE-2014-4660
Summary
| CVE | CVE-2014-4660 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-20 03:15:00 UTC |
| Updated | 2020-02-25 20:13:00 UTC |
| Description | Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ansible/CHANGELOG.md at release1.5.5 · ansible/ansible · GitHub | MISC | github.com | Release Notes |
| Backporting apt_repository module from devel · ansible/ansible@c4b5e46 · GitHub | MISC | github.com | Patch |
| oss-security - Re: Ansible CVE requests | MISC | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| CVE-2014-4660 | MISC | security-tracker.debian.org | Patch, Third Party Advisory |
| ansible CVE-2014-4660 Remote Information Disclosure Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.