mirror of https://github.com/ansible/ansible.git
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
* Change default file permissions so they are not world readable
CVE-2020-1736
Set the default permissions for files we create with atomic_move() to 0o0660. Track
which files we create that did not exist and warn if the module supports 'mode'
and it was not specified and the module did not call set_mode_if_different(). This allows the user to take action and specify a mode rather than using the defaults.
A code audit is needed to find all instances of modules that call atomic_move()
but do not call set_mode_if_different(). The findings need to be documented in
a changelog since we are not warning. Warning in those instances would be frustrating
to the user since they have no way to change the module code.
- use a set for storing list of created files
- just check the argument spac and params rather than using another property
- improve the warning message to include the default permissions.
(cherry picked from commit
|
5 years ago | |
|---|---|---|
| .. | ||
| common | 5 years ago | |
| compat | 6 years ago | |
| csharp | 6 years ago | |
| distro | 6 years ago | |
| facts | 5 years ago | |
| parsing | 5 years ago | |
| powershell | 6 years ago | |
| six | 7 years ago | |
| __init__.py | 8 years ago | |
| _text.py | 5 years ago | |
| ansible_release.py | 8 years ago | |
| api.py | 5 years ago | |
| basic.py | 5 years ago | |
| connection.py | 5 years ago | |
| json_utils.py | 5 years ago | |
| pycompat24.py | 5 years ago | |
| service.py | 5 years ago | |
| splitter.py | 5 years ago | |
| urls.py | 5 years ago | |
| yumdnf.py | 5 years ago | |