Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp9j-rghq-8jhh

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 2
CVSS3: 5

Описание

Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

>= 2.10.0a1, < 2.10.0rc1

2.10.0rc1

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.9.12

2.9.12

EPSS

Процентиль: 11%
0.00038
Низкий

2 Low

CVSS4

5 Medium

CVSS3

Дефекты

CWE-362
CWE-377
CWE-668

Связанные уязвимости

CVSS3: 5
ubuntu
больше 5 лет назад

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

CVSS3: 5
redhat
больше 5 лет назад

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

CVSS3: 5
nvd
больше 5 лет назад

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

CVSS3: 5
msrc
больше 5 лет назад

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18 2.8.12 and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5 3.5.6 and 3.6.4 as well as previous versions are affected.

CVSS3: 5
debian
больше 5 лет назад

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansi ...

EPSS

Процентиль: 11%
0.00038
Низкий

2 Low

CVSS4

5 Medium

CVSS3

Дефекты

CWE-362
CWE-377
CWE-668