CVE-2021-3701

Publication date 23 August 2022

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.6 · Medium

Score breakdown

A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity.

Status

Package Ubuntu Release Status
ansible-runner 23.10 mantic
Not affected
23.04 lunar
Not affected
22.10 kinetic Ignored end of life, was needs-triage
22.04 LTS jammy
Not affected
21.10 impish Ignored end of life
21.04 hirsute Not in release
20.04 LTS focal Not in release
18.04 LTS bionic Not in release
16.04 LTS xenial Ignored end of standard support
14.04 LTS trusty Not in release

Severity score breakdown

Parameter Value
Base score 6.6 · Medium
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N