Safety vulnerability ID: 42918
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Ansible 1.5.5 includes a fix for CVE-2014-4660: Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
https://www.openwall.com/lists/oss-security/2014/06/26/19
Latest version: 11.1.0
Radically simple IT automation
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application