Medium severity5.5NVD Advisory· Published Feb 20, 2020· Updated Jun 17, 2026
CVE-2014-4660
CVE-2014-4660
Description
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ansiblePyPI | < 1.5.5 | 1.5.5 |
Affected products
3- Ansible/Ansibledescription
Patches
Vulnerability mechanics
References
9- github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08nvdPatchWEB
- security-tracker.debian.org/tracker/CVE-2014-4660nvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/06/26/19nvdMailing ListPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5xm4-jmpw-p6j3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-4660ghsaADVISORY
- www.securityfocus.com/bid/68231nvdThird Party AdvisoryVDB Entry
- github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.mdnvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-202.yamlghsaWEB
- web.archive.org/web/20200229060002/https://www.securityfocus.com/bid/68231ghsaWEB
News mentions
0No linked articles in our index yet.