CVE-2021-3532: Infoleak
A flaw was found in Ansible where the secret information present in asyncfiles are getting disclosed when the user changes the jobdir to a world readable directory. Any secret information in an async status file will be readable by a malicious user on that system. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.
Other sources
Rejected reason: This CVE is marked as INVALID and not a bug
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID is CVE-2021-3532.
What is the severity rating of CVE-2021-3532?
The severity rating of CVE-2021-3532 is medium (5.5 out of 10).
Which software versions are affected by CVE-2021-3532?
Redhat Ansible Automation Platform 1.2, Redhat Ansible Tower 3.7.0, Redhat Ansible Engine 2.0, Redhat Ansible Tower 3.0, Redhat Enterprise Linux 7.0, Fedoraproject Fedora 34, and Redhat Openstack-rdo are affected by CVE-2021-3532.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-3532?
The Common Weakness Enumeration (CWE) ID for CVE-2021-3532 is CWE-732 and CWE-200.
Is there a fix available for CVE-2021-3532?
Yes, a fix is available for CVE-2021-3532. It is recommended to update to the latest version of the affected software.