CVE-2014-4660
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-4660
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1.5.5+dfsg-1 |
| debian | forky | fixed | 1.5.5+dfsg-1 |
| debian | bullseye | fixed | 1.5.5+dfsg-1 |
| debian | sid | fixed | 1.5.5+dfsg-1 |
| debian | trixie | fixed | 1.5.5+dfsg-1 |
References
- https://security-tracker.debian.org/tracker/CVE-2014-4660
- https://nvd.nist.gov/vuln/detail/CVE-2014-4660
- https://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08
- https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.md
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-202.yaml
- https://web.archive.org/web/20200229060002/https://www.securityfocus.com/bid/68231
- https://www.openwall.com/lists/oss-security/2014/06/26/19
- https://www.securityfocus.com/bid/68231
Verify integrity in audit chain (admin only). AS-IS.