Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-3702
HistoryAug 23, 2022 - 4:15 p.m.

Race condition

2022-08-2316:15:00
PRIOn knowledge base
www.prio-n.com
4
race condition
ansible-runner
unauthorized access
private data dir
integrity
confidentiality

6.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%

A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner’s private_data_dir the next time ansible-runner made use of the private_data_dir. The highest Threat out of this flaw is to integrity and confidentiality.

CPENameOperatorVersion
ansible_runnereq2.0.0

6.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%