PT-2021-20890 · Red Hat · Ansible Automation Platform+2

Published

2021-06-09

·

Updated

2024-01-23

·

CVE-2021-3533

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Ansible Tower version 3.7 Ansible Automation Platform version 1.2
Description: A flaw was found in Ansible related to the setting of the ANSIBLE ASYNC DIR variable to a subdirectory of a world-writable directory, leading to a race condition on the managed machine. This issue can be exploited by a malicious, non-privileged account on the remote machine to access async result data.
Recommendations: For Ansible Tower version 3.7, avoid setting ANSIBLE ASYNC DIR to a subdirectory of a world-writable directory to prevent the race condition. For Ansible Automation Platform version 1.2, restrict access to world-writable directories to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2021-3533
PYSEC-2021-126

Affected Products

Ansible
Ansible Automation Platform
Ansible Tower