CVE-2020-10744
published 2020-05-15CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The…
PriorityP421medium5CVSS 3.1
AVLACHPRLUIRSCCLILAL
EPSS
0.26%
17.1th percentile
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.13+dfsg-1 (bookworm) | ansible 2.9.13+dfsg-1 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_ansible_2.9.18-1_on_cbl_mariner_1.0 | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.12 | 2.9.12 |
| redhat | ansible | >= 0 < 2.0.0.2-2ubuntu1.3+esm1 | 2.0.0.2-2ubuntu1.3+esm1 |
| redhat | ansible | >= 0 < 2.5.1+dfsg-1ubuntu0.1+esm1 | 2.5.1+dfsg-1ubuntu0.1+esm1 |
| redhat | ansible | >= 0 < 2.9.6+dfsg-1ubuntu0.1~esm1 | 2.9.6+dfsg-1ubuntu0.1~esm1 |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm1 | 2.10.7+merged+base+2.10.8+dfsg-1ubuntu0.1~esm1 |
| redhat | ansible | >= 2.10.0a1 < 2.10.0rc1 | 2.10.0rc1 |
| redhat | ansible | 2.7.0 – 2.7.18 | — |
| redhat | ansible | 2.8.0 – 2.8.12 | — |
| redhat | ansible | 2.9.0 – 2.9.9 | — |
| redhat | ansible_tower | 3.4.0 – 3.4.5 | — |
| redhat | ansible_tower | 3.5.0 – 3.5.6 | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ansible vulnerabilities
vendor_ubuntu·2022-06-07·CVSS 5.0
CVE-2020-10744 [MEDIUM] Ansible vulnerabilities
Title: Ansible vulnerabilities
Summary: Several security issues were fixed in Ansible.
It was discovered that Ansible did not properly manage directory
permissions when running playbooks with an unprivileged become user. A
local attacker could possibly use this issue to cause a race condition,
escalate privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-1733)
It was discovered that the fix to address CVE-2020-1733 in Ansible was
incomplete on systems using ACLs and FUSE filesystems. A local attacker
could possibly use this issue to cause a race condition, escalate
privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-10744)
It was d
Red Hat
ansible: incomplete fix for CVE-2020-1733
vendor_redhat·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CWE-377 ansible: incomplete fix for CVE-2020-1733
ansible: incomplete fix for CVE-2020-1733
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
An incomplete fix was found for the fix of the flaw CVE-2020-1733, Ansible: insecure temporary directory when running become_user from the become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems.
Statement: Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as pr
Microsoft
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the
vendor_msrc·2020-05-12·CVSS 5.0
CVE-2020-10744 [MEDIUM] CWE-362 An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18 2.8.12 and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5 3.5.6 and 3.6.4 as well as previous versions are affected.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compos
Debian
CVE-2020-10744: ansible - An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insec...
vendor_debian·2020·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744: ansible - An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insec...
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
Scope: local
bookworm: resolved (fixed in 2.9.13+dfsg-1)
bullseye: resolved (fixed in 2.9.13+dfsg-1)
forky: resolved (fixed in 2.9.13+dfsg-1)
sid: resolved (fixed in 2.9.13+dfsg-1)
trixie: resolved (fixed in 2.9.13+dfsg-1)
OSV
ansible vulnerabilities
osv·2022-06-07·CVSS 5.0
CVE-2020-1733 [MEDIUM] ansible vulnerabilities
ansible vulnerabilities
It was discovered that Ansible did not properly manage directory
permissions when running playbooks with an unprivileged become user. A
local attacker could possibly use this issue to cause a race condition,
escalate privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-1733)
It was discovered that the fix to address CVE-2020-1733 in Ansible was
incomplete on systems using ACLs and FUSE filesystems. A local attacker
could possibly use this issue to cause a race condition, escalate
privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-10744)
It was discovered that Ansible did not properly manage multi-line YAML
s
OSV
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
osv·2022-02-09·CVSS 5.0
CVE-2020-10744 [MEDIUM] Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
GHSA
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
ghsa·2022-02-09·CVSS 5.0
CVE-2020-10744 [MEDIUM] CWE-362 Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
OSV
CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
osv·2020-05-15·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [fedora-all]
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [fedora-all]
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [openstack-rdo]
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [openstack-rdo]
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
RDO includes openstack-ansible-core-2.14.
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733
This flaw refers to the incomplete fix for CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. This vulnerability seems not mitigated fully as there race condition from the original flaw could still happen on systems using ACLs and FUSE filesystems. The 'mkdir -p' is insecure by design.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Mitigation:
Currently, there is no mitigation for this issue.
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1835854]
Affects: fedora-all [bug 1835855]
Affects: openstack-rdo [bug 1835856]
---
Borja, has tis incomplete fix already been reported upstream?
---
In reply
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [epel-all]
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [epel-all]
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora E
2020-05-15
Published