Lucene search

K
osvGoogleOSV:GHSA-PCQV-C46V-2P4V
HistoryMay 14, 2022 - 2:03 a.m.

Ansible Arbitrary File Overwrite Vulnerability

2022-05-1402:03:36
Google
osv.dev
10
ansible
arbitrary file overwrite
vulnerability
playbook
local users
symlink attack
retry file
predictable name

EPSS

0

Percentile

5.1%

lib/ansible/playbook/init.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in /var/tmp/ansible/.