GHSA-6667-f46p-pg88
Dashboard / Vulnerabilities / GHSA-6667-f46p-pg88
GHSA-6667-f46p-pg88
Summary: Ansible sets unsafe permissions for sources.list
Details: Ansible before 1.5.5 sets 0644 permissions for `sources.list`, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the `"deb http://user:pass@server:port/"` format.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-4659, https://github.com/ansible/ansible/commit/a0e027fe362fbc209dbeff2f72d6e95f39885c69, https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.md, https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-201.yaml, https://web.archive.org/web/20200229060001/https://www.securityfocus.com/bid/68234
Affected packages
Package
Name: ansible
Purl: pkg:pypi/ansible
Affected ranges
Type: ECOSYSTEM
Events:
