CVE-2014-4659: Red Hat Ansible

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

Affected products

  • Red Hat Ansible: before 1.5.5 (fixed in 1.5.5)

Published 2020-02-20. Last modified 2026-06-17.