Changed |
Description |
A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world writable directory. When this occurs, there is a race condition on the managed machine. A malicious, non-privileged account on the remote machine can exploit the race condition to access the async result data. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.
|
Rejected reason: This CVE is marked as INVALID and not a bug
|
Removed |
CVSS V3.1 |
NIST AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
|
Removed |
CVSS V2 |
NIST (AV:L/AC:H/Au:N/C:P/I:N/A:N)
|
|
Removed |
CWE |
NIST CWE-362
|
|
Removed |
CWE |
Red Hat, Inc. CWE-367
|
|
Removed |
CPE Configuration |
OR
*cpe:2.3:a:redhat:ansible_tower:3.7.0:*:*:*:*:*:*:*
*cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:*
|
|
Removed |
CPE Configuration |
OR
*cpe:2.3:a:redhat:openstack-rdo:-:*:*:*:*:*:*:*
|
|
Removed |
CPE Configuration |
OR
*cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
|
|
Removed |
CPE Configuration |
OR
*cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
*cpe:2.3:a:redhat:ansible_engine:2.0:*:*:*:*:*:*:*
*cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:*
|
|
Removed |
Reference |
Red Hat, Inc. https://bugzilla.redhat.com/show_bug.cgi?id=1956477
|
|