CVE-2014-4658: Red Hat Ansible
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.
Affected products
- Red Hat Ansible: before 1.5.5 (fixed in 1.5.5)
Published 2020-02-20. Last modified 2026-06-17.