A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity.
During installation, installed file permissions are set to allow anyone to modify those files.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Ansible_runner | Redhat | 2.0.0 (including) | 2.0.0 (including) | 
| Ansible-runner | Ubuntu | impish | * | 
| Ansible-runner | Ubuntu | kinetic | * | 
| Ansible-runner | Ubuntu | trusty | * | 
| Ansible-runner | Ubuntu | upstream | * | 
| Ansible-runner | Ubuntu | xenial | * |