Back to search
CVE-2014-4660
Published: Feb 20, 2020
Modified: Aug 6, 2024
PUBLISHED
Description
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.securityfocus.com/bid/68231
x_refsource_MISC
https://www.openwall.com/lists/oss-security/2014/06/26/19
x_refsource_MISC
https://security-tracker.debian.org/tracker/CVE-2014-4660
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now