ID |
CVE-2021-3701
|
Sažetak |
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity. |
Reference |
|
CVSS |
Base: | 6.6 |
Impact: | 5.2 |
Exploitability: | 1.3 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
LOW |
- |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
HIGH |
HIGH |
NONE |
|
CVSS vektor |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Zadnje važnije ažuriranje |
17-02-2023 - 19:06 |
Objavljeno |
23-08-2022 - 16:15 |