Safety vulnerability ID: 25618
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Ansible 1.5.5 includes a fix for CVE-2014-4658: The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.
Latest version: 11.1.0
Radically simple IT automation
- Security fix for vault, to ensure the umask is set to a restrictive mode before creating/editing vault files.
- Backported apt_repository security fixes relating to filename/mode upon sources list file creation.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application