---
title: "CVE-2014-4660\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-4660?format=md
keywords: index, follow
---

# CVE-2014-4660

Publication date 20 February 2020

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2014-4660?format=md#impact-score)

Toggle side navigation

## Description

Ansible before 1.5.5 constructs filenames containing user and password
fields on the basis of deb lines in sources.list, which might allow local
users to obtain sensitive credential information in opportunistic
circumstances by leveraging existence of a file that uses the "deb
http://user:pass@server:port/" format.

### From the Ubuntu Security Team

It was discovered that Ansible created filenames containing sensitive information.
An attacker could use this vulnerability to obtain unauthorized access to a
private Ubuntu repository.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ansible | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Fixed 1.5.4+dfsg-1ubuntu0.1~esm2  Ubuntu Pro |
| 13.10 saucy | Ignored end of life |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-4660?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| ansible | * Upstream:   [c4b5e46](https://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4660)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-4660)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-4660)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-4660)

### Other references

* <http://www.openwall.com/lists/oss-security/2014/06/26/19>
* <https://www.cve.org/CVERecord?id=CVE-2014-4660>
