QID 997081
Date Published: 2024-02-02
QID 997081: Python (Pip) Security Update for ansible (GHSA-6667-f46p-pg88)
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6667-f46p-pg88 for updates and patch information.
Vendor References
- GHSA-6667-f46p-pg88 -
github.com/advisories/GHSA-6667-f46p-pg88
CVEs related to QID 997081
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6667-f46p-pg88 | ansible |
|