Ansible discloses credential information
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Sep 10, 2024
Description
Published by the National Vulnerability Database
Feb 20, 2020
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Aug 16, 2023
Last updated
Sep 10, 2024
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in
sources.list
, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses thedeb http://user:pass@server:port/
format.References