Lucene search

K
osvGoogleOSV:GHSA-5G4V-2PC6-4HH4
HistoryMay 17, 2022 - 7:57 p.m.

Ansible Sensitive Files Are Locally Readable

2022-05-1719:57:32
Google
osv.dev
2

0.0004 Low

EPSS

Percentile

5.1%

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

0.0004 Low

EPSS

Percentile

5.1%