CVE-2014-4660

CVE-2014-4660

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.

Source: CVE-2014-4660

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다