U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-3533

Change History

CVE Modified by Red Hat, Inc. 1/15/2024 12:15:08 PM

Action Type Old Value New Value
Removed CPE Configuration
OR
     
          *cpe:2.3:a:redhat:ansible_tower:3.7.0:*:*:*:*:*:*:*
          *cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:*

								
						
Removed CPE Configuration
OR
     
          *cpe:2.3:a:redhat:openstack-rdo:-:*:*:*:*:*:*:*

								
						
Removed CPE Configuration
OR
     
          *cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

								
						
Removed CPE Configuration
OR
     
          *cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
          *cpe:2.3:a:redhat:ansible_engine:2.0:*:*:*:*:*:*:*
          *cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:*

								
						
Removed CVSS V2
NIST (AV:L/AC:H/Au:N/C:P/I:N/A:N)

								
						
Removed CVSS V3.1
NIST AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

								
						
Removed CWE
NIST CWE-362

								
						
Removed CWE
Red Hat, Inc. CWE-367

								
						
Changed Description
A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world writable directory. When this occurs, there is a race condition on the managed machine. A malicious, non-privileged account on the remote machine can exploit the race condition to access the async result data. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.
Rejected reason: This CVE is marked as INVALID and not a bug
Removed Reference
Red Hat, Inc. https://bugzilla.redhat.com/show_bug.cgi?id=1956477

								
						

CVE Translated by Red Hat, Inc. 1/15/2024 12:15:08 PM

Action Type Old Value New Value
Removed Translation
Title: la función ANSIBLE_ASYNC_DIR en Ansible
Description: Se encontró un fallo en Ansible si un usuario ansible ajusta la función ANSIBLE_ASYNC_DIR en un subdirectorio de un directorio world writable. Cuando esto ocurre, se presenta una condición de carrera en la máquina administrada. Una cuenta maliciosa y no privilegiada en la máquina remota puede explotar la condición de carrera para acceder a los datos de resultados asincrónicos. Este fallo afecta a Ansible Tower versión 3.7 y Ansible Automation Platform versión 1.2

								
						

CVE Rejected by Red Hat, Inc. 1/15/2024 12:15:08 PM

Action Type Old Value New Value