CVE Vulnerabilities

CVE-2014-4660

Insufficiently Protected Credentials

Published: Feb 20, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the deb http://user:pass@server:port/ format.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
AnsibleRedhat*1.5.5 (excluding)
AnsibleUbuntuesm-infra-legacy/trusty*
AnsibleUbuntusaucy*
AnsibleUbuntutrusty*
AnsibleUbuntutrusty/esm*
AnsibleUbuntuupstream*

Potential Mitigations

References