mirror of https://github.com/ansible/ansible.git
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
* [stable-2.9] Change default file permissions so they are not world readable (#70221) * Change default file permissions so they are not world readable CVE-2020-1736 Set the default permissions for files we create with atomic_move() to 0o0660. Track which files we create that did not exist and warn if the module supports 'mode' and it was not specified and the module did not call set_mode_if_different(). This allows the user to take action and specify a mode rather than using the defaults. A code audit is needed to find all instances of modules that call atomic_move() but do not call set_mode_if_different(). The findings need to be documented in a changelog since we are not warning. Warning in those instances would be frustrating to the user since they have no way to change the module code. - use a set for storing list of created files - just check the argument spac and params rather than using another property - improve the warning message to include the default permissions. (cherry picked from commit |
5 years ago | |
|---|---|---|
| .. | ||
| acme | 6 years ago | |
| aws | 7 years ago | |
| basic | 5 years ago | |
| cloud | 7 years ago | |
| common | 6 years ago | |
| docker | 6 years ago | |
| ec2 | 7 years ago | |
| facts | 5 years ago | |
| gcp | 7 years ago | |
| hwc | 7 years ago | |
| identity/keycloak | 6 years ago | |
| json_utils | 7 years ago | |
| net_tools | 7 years ago | |
| network | 6 years ago | |
| parsing | 9 years ago | |
| postgresql | 7 years ago | |
| remote_management | 7 years ago | |
| urls | 6 years ago | |
| xenserver | 6 years ago | |
| __init__.py | 9 years ago | |
| conftest.py | 7 years ago | |
| test_api.py | 5 years ago | |
| test_database.py | 7 years ago | |
| test_distribution_version.py | 7 years ago | |
| test_distro.py | 7 years ago | |
| test_hetzner.py | 7 years ago | |
| test_known_hosts.py | 7 years ago | |
| test_kubevirt.py | 7 years ago | |
| test_netapp.py | 6 years ago | |
| test_text.py | 8 years ago | |
| test_utm_utils.py | 7 years ago | |
| test_vmware.py | 6 years ago | |