cbcvebase.
CVE-2020-10744
published 2020-05-15

CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The…

medium5CVSS 3.1
AVLACHPRLUIRSCCLILAL
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianansible< ansible 2.9.13+dfsg-1 (bookworm)ansible 2.9.13+dfsg-1 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_ansible_2.9.18-1_on_cbl_mariner_1.0
red_hatansible
red_hatansible
red_hatansible
red_hatansible
red_hatansible
red_hatansible
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.13+dfsg-12.9.13+dfsg-1
redhatansible>= 0 < 2.9.122.9.12
redhatansible>= 0 < 2.0.0.2-2ubuntu1.3+esm12.0.0.2-2ubuntu1.3+esm1
redhatansible>= 0 < 2.5.1+dfsg-1ubuntu0.1+esm12.5.1+dfsg-1ubuntu0.1+esm1
redhatansible>= 0 < 2.9.6+dfsg-1ubuntu0.1~esm12.9.6+dfsg-1ubuntu0.1~esm1
redhatansible>= 0 < 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm12.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm1
redhatansible>= 2.10.0a1 < 2.10.0rc12.10.0rc1
redhatansible2.7.0 – 2.7.18
redhatansible2.8.0 – 2.8.12
redhatansible2.9.0 – 2.9.9
redhatansible_tower3.4.0 – 3.4.5
redhatansible_tower3.5.0 – 3.5.6

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
ghsa5.0MEDIUM
osv5.0MEDIUM