REDHAT-BUG-1977965: Race Condition
A race condition was found in ansible-runner where an attacker could watch for a rapid creation and deletion of a temporary directory, substitute their own directory at that name, and then have access to ansible-runner's privatedatadir the next time ansible-runner made use of the privatedatadir.
Upstream patch:
https://github.com/ansible/ansible-runner/pull/742/commits/0e9aa8a97e7832ef9a1553ef2908632a32d2b8c4
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1977965?
The severity of REDHAT-BUG-1977965 is considered to be high due to the potential for unauthorized access to sensitive data.
How do I fix REDHAT-BUG-1977965?
To fix REDHAT-BUG-1977965, upgrade to the patched version of ansible-runner that addresses the race condition.
Who is affected by REDHAT-BUG-1977965?
Users of Ansible ansible-runner are affected by REDHAT-BUG-1977965, especially those using versions vulnerable to the race condition.
What is the nature of the vulnerability in REDHAT-BUG-1977965?
The vulnerability in REDHAT-BUG-1977965 is a race condition allowing attackers to intercept and manipulate temporary directories.
When was REDHAT-BUG-1977965 reported?
REDHAT-BUG-1977965 was reported in 2023 but specific dates may vary by the issue tracking system.