ansible-runner: Race condition with temporary files in tempfile.TemporaryDirectory()
Published Aug 23, 2022
5.3
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of the private_data_dir. The highest Threat out of this flaw is to integrity and confidentiality.
Affected products
- Vendor n/a Product Ansible-Runner Defaultn/a
- Version Affects ansible-runner 2.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ansible-Runner | n/a |
|
- 2.0.0
No data.
CloudForms Management Engine 5
ansible-runner
Not affected
Red Hat Ansible Automation Platform 1.2
ansible-runner
Not affected
Red Hat Ansible Automation Platform 2
ansible-runner
Not affected
Red Hat Ansible Tower 3
ansible-runner
Not affected
Red Hat Ansible Tower 3
python2-ansible-runner
Not affected
Red Hat Ansible Tower 3
python3-ansible-runner
Not affected
Red Hat Ceph Storage 4
ansible-runner
Not affected
Red Hat OpenShift Container Platform 3.11
ansible-runner
Not affected
Red Hat OpenShift Container Platform 4
ansible-runner
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-ansible-runner
Not affected
Red Hat OpenStack Platform 16 (Train)
python-ansible-runner
Not affected
Red Hat Satellite 6
ansible-runner
Not affected
Red Hat Virtualization 4
ansible-runner
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | ansible-runner | Not affected | n/a |
| Red Hat Ansible Automation Platform 1.2 | ansible-runner | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-runner | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible-runner | Not affected | n/a |
| Red Hat Ansible Tower 3 | python2-ansible-runner | Not affected | n/a |
| Red Hat Ansible Tower 3 | python3-ansible-runner | Not affected | n/a |
| Red Hat Ceph Storage 4 | ansible-runner | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | ansible-runner | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | ansible-runner | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-ansible-runner | Not affected | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-ansible-runner | Not affected | n/a |
| Red Hat Satellite 6 | ansible-runner | Not affected | n/a |
| Red Hat Virtualization 4 | ansible-runner | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2021-3702 x_refsource_MISCVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1977965 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0005 Advisory
- https://github.com/advisories/GHSA-772j-xvf9-qpf5 Advisory
- https://github.com/ansible/ansible-runner/commit/93e95a3df9021a38010386d07df121392d249253
- https://github.com/ansible/ansible-runner/pull/742
- https://github.com/ansible/ansible-runner/pull/742/commits x_refsource_MISCPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible-runner/PYSEC-2022-43068.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2021-3702
- https://www.cve.org/CVERecord?id=CVE-2021-3702
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3702 | x_refsource_MISCVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1977965 | x_refsource_MISCIssue TrackingPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0005 | Advisory | |
| https://github.com/advisories/GHSA-772j-xvf9-qpf5 | Advisory | |
| https://github.com/ansible/ansible-runner/commit/93e95a3df9021a38010386d07df121392d249253 | ||
| https://github.com/ansible/ansible-runner/pull/742 | ||
| https://github.com/ansible/ansible-runner/pull/742/commits | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/ansible-runner/PYSEC-2022-43068.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2021-3702 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-3702 |
Change history (0)
No recorded changes yet.