Source: ansible
X-Debbugs-CC: t...@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for ansible.

CVE-2021-3533[0]:
| A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR
| to a subdirectory of a world writable directory. When this occurs,
| there is a race condition on the managed machine. A malicious, non-
| privileged account on the remote machine can exploit the race
| condition to access the async result data. This flaw affects Ansible
| Tower 3.7 and Ansible Automation Platform 1.2.

This was reported at Red Hat:   
https://bugzilla.redhat.com/show_bug.cgi?id=1956477

It needs to be checked if this was reported/fixed upstream.     

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-3533
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3533

Please adjust the affected versions in the BTS as needed.

Reply via email to