CVE-2014-4659: Medium severity red hat ansible vulnerability
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Other sources
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-4659?
CVE-2014-4659 is a vulnerability in Ansible before version 1.5.5 that sets 0644 permissions for sources.list, potentially allowing local users to obtain sensitive credential information.
How does CVE-2014-4659 affect Ansible?
CVE-2014-4659 affects Ansible versions before 1.5.5 where it sets permissions that can potentially be exploited by local users to access sensitive credential information.
What is the severity of CVE-2014-4659?
The severity of CVE-2014-4659 is medium with a severity value of 5.5.
How can I fix CVE-2014-4659 in Ansible?
To fix CVE-2014-4659, update Ansible to version 1.5.5 or later.
Where can I find more information about CVE-2014-4659?
You can find more information about CVE-2014-4659 in the following references: [GitHub](https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.md) and [SecurityFocus](https://www.securityfocus.com/bid/68234).