A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world writable directory. When this occurs, there is a race condition on the managed machine. A malicious, non-privileged account on the remote machine can exploit the race condition to access the async result data. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1956477 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2021-06-09 05:15
Updated : 2022-04-25 10:24
NVD link : CVE-2021-3533
Mitre link : CVE-2021-3533
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
redhat
- ansible_engine
- enterprise_linux
- openstack-rdo
- ansible_automation_platform
- ansible_tower
fedoraproject
- fedora