Description
A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of the private_data_dir. The highest Threat out of this flaw is to integrity and confidentiality.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0005 | A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of the private_data_dir. The highest Threat out of this flaw is to integrity and confidentiality. |
Github GHSA |
GHSA-772j-xvf9-qpf5 | ansible-runner vulnerable to Race Condition |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:07.921Z
Reserved: 2021-08-12T00:00:00.000Z
Link: CVE-2021-3702
No data.
Status : Modified
Published: 2022-08-23T16:15:09.550
Modified: 2024-11-21T06:22:11.477
Link: CVE-2021-3702
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA