CVE-2014-4660
published 2020-02-20CVE-2014-4660: Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.38%
30.6th percentile
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 1.5.5+dfsg-1 (bookworm) | ansible 1.5.5+dfsg-1 (bookworm) |
| redhat | ansible | < 1.5.5 | 1.5.5 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| redhat | ansible | >= 0 < 1.5.5 | 1.5.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ansible discloses credential information
ghsa·2022-05-17
CVE-2014-4660 [MEDIUM] CWE-200 Ansible discloses credential information
Ansible discloses credential information
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in `sources.list`, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the `deb http://user:pass@server:port/` format.
OSV
Ansible discloses credential information
osv·2022-05-17
CVE-2014-4660 [MEDIUM] Ansible discloses credential information
Ansible discloses credential information
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in `sources.list`, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the `deb http://user:pass@server:port/` format.
OSV
CVE-2014-4660: Ansible before 1
osv·2020-02-20·CVSS 5.5
CVE-2014-4660 [MEDIUM] CVE-2014-4660: Ansible before 1
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
Debian
CVE-2014-4660: ansible - Ansible before 1.5.5 constructs filenames containing user and password fields on...
vendor_debian·2014·CVSS 5.5
CVE-2014-4660 [MEDIUM] CVE-2014-4660: ansible - Ansible before 1.5.5 constructs filenames containing user and password fields on...
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
forky: resolved (fixed in 1.5.5+dfsg-1)
sid: resolved (fixed in 1.5.5+dfsg-1)
trixie: resolved (fixed in 1.5.5+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdhttps://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08https://security-tracker.debian.org/tracker/CVE-2014-4660https://www.openwall.com/lists/oss-security/2014/06/26/19https://www.securityfocus.com/bid/68231https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdhttps://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08https://security-tracker.debian.org/tracker/CVE-2014-4660https://www.openwall.com/lists/oss-security/2014/06/26/19https://www.securityfocus.com/bid/68231
2020-02-20
Published