Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3701
HistoryAug 23, 2022 - 3:50 p.m.

CVE-2021-3701

2022-08-2315:50:47
CWE-276
redhat
www.cve.org
1

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity.

CNA Affected

[
  {
    "product": "ansible-runner",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Affects ansible-runner 2.0"
      }
    ]
  }
]

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%