Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-9902

Опубликовано: 06 нояб. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.3

Описание

A flaw was found in Ansible. The ansible-core user module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the user module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

noble

needs-triage

oracular

ignored

end of life, was needs-triage
plucky

needs-triage

questing

needs-triage

Показывать по

EPSS

Процентиль: 16%
0.00067
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
около 1 года назад

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.

CVSS3: 6.3
nvd
около 1 года назад

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.

CVSS3: 6.3
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.3
debian
около 1 года назад

A flaw was found in Ansible. The ansible-core `user` module can allow ...

CVSS3: 6.3
github
около 1 года назад

ansible-core Incorrect Authorization vulnerability

EPSS

Процентиль: 16%
0.00067
Низкий

6.3 Medium

CVSS3