Описание
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
Меры по смягчению последствий
The following practices would help for avoiding exposure and mitigate this flaw:
- Do not run the ansible.posix authorized_key module with elevated privileges against untrusted user accounts.
- Validate that target user home directories do not contain unexpected symbolic links before running playbooks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rhel-system-roles | Not affected | ||
| Red Hat Enterprise Linux 8 | rhc-worker-playbook | Affected | ||
| Red Hat Enterprise Linux 8 | rhel-system-roles | Not affected | ||
| Red Hat Enterprise Linux 9 | rhel-system-roles | Not affected | ||
| Red Hat OpenStack Platform 17.1 | ansible-collection-ansible-posix | Affected | ||
| Red Hat OpenStack Platform 18.0 | ansible-collection-ansible-posix | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
A local privilege escalation vulnerability was found in the ansible.po ...
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
Уязвимость функции keyfile() модуля ansible.posix.authorized_key, позволяющая нарушителю повысить свои привилегии
EPSS
7.3 High
CVSS3