CVE-2021-3702: Race Condition
A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's privatedatadir the next time ansible-runner made use of the privatedatadir. The highest Threat out of this flaw is to integrity and confidentiality.
Other sources
A race condition was found in ansible-runner where an attacker could watch for a rapid creation and deletion of a temporary directory, substitute their own directory at that name, and then have access to ansible-runner's privatedatadir the next time ansible-runner made use of the privatedatadir.
Upstream patch:
https://github.com/ansible/ansible-runner/pull/742/commits/0e9aa8a97e7832ef9a1553ef2908632a32d2b8c4
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3702?
CVE-2021-3702 has been classified with a medium severity level due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2021-3702?
To mitigate CVE-2021-3702, upgrade ansible-runner to version 2.1.0 or later.
What components are affected by CVE-2021-3702?
CVE-2021-3702 affects ansible-runner versions from 2.0.0 to below 2.1.0.
What type of vulnerability is CVE-2021-3702?
CVE-2021-3702 is a race condition vulnerability that can be exploited to gain access to private directories.
Who is the vendor affected by CVE-2021-3702?
CVE-2021-3702 affects Red Hat's ansible-runner software.