Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4152
HistoryMay 03, 2017 - 8:20 a.m.

Information Disclosure

2017-05-0308:20:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.0004 Low

EPSS

Percentile

5.1%

ansible is vulnerable to information disclosure. The application can leak vulnerable information when the /etc/apt/sources.list file encounters a line starting with deb http://user:pass@server:port/. This can then be used to construct a file containing the user and pass fields, thereby leaking credentials.

CPENameOperatorVersion
ansiblele1.5.4

0.0004 Low

EPSS

Percentile

5.1%