CVE-2014-4658

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
20/02/2020
Last modified:
25/02/2020

Description

The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:* 1.5.5 (excluding)