Ansible Arbitrary File Overwrite Vulnerability
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Sep 4, 2024
Description
Published by the National Vulnerability Database
Sep 16, 2013
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Aug 28, 2023
Last updated
Sep 4, 2024
lib/ansible/playbook/__init__.py
in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in/var/tmp/ansible/
.References