CVE Database
/

CVE-2020-10744

Back to search

CVE-2020-10744

Published: May 15, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

5.0

MEDIUM

Description

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

VendorProductVersions

Red Hat

ansible

affected
ansible-engine 2.7.18 and prior
affected
ansible-engine 2.8.12 and prior
affected
ansible-engine 2.9.9 and prior
affected
ansible-tower 3.4.5 and prior
affected
ansible-tower 3.5.6 and prior

+1 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

Attack Vector

Local

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now