CVE Vulnerabilities

CVE-2020-10744

Insecure Temporary File

Published: May 15, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Ubuntu
LOW

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

Weakness

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Affected Software

Name Vendor Start Version End Version
Ansible Redhat 2.7.0 (including) 2.7.18 (including)
Ansible Redhat 2.8.0 (including) 2.8.12 (including)
Ansible Redhat 2.9.0 (including) 2.9.9 (including)
Ansible_tower Redhat 3.4.0 (including) 3.4.5 (including)
Ansible_tower Redhat 3.5.0 (including) 3.5.6 (including)
Ansible_tower Redhat 3.6.0 (including) 3.6.4 (including)
Ansible Ubuntu bionic *
Ansible Ubuntu eoan *
Ansible Ubuntu esm-apps/bionic *
Ansible Ubuntu esm-apps/focal *
Ansible Ubuntu esm-apps/xenial *
Ansible Ubuntu esm-infra-legacy/trusty *
Ansible Ubuntu focal *
Ansible Ubuntu groovy *
Ansible Ubuntu hirsute *
Ansible Ubuntu trusty *
Ansible Ubuntu trusty/esm *
Ansible Ubuntu upstream *
Ansible Ubuntu xenial *

References