Lucene search

K
osvGoogleOSV:GHSA-6667-F46P-PG88
HistoryMay 17, 2022 - 7:57 p.m.

Ansible sets unsafe permissions for sources.list

2022-05-1719:57:32
Google
osv.dev
4

6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%