CVE-2020-1733
published 2020-03-11CVE-2020-1733: A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user…
PriorityP422medium5CVSS 3.1
AVLACHPRLUIRSCCLILAL
EPSS
0.40%
32.3th percentile
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc//cmdline'.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.7+dfsg-1 (bookworm) | ansible 2.9.7+dfsg-1 (bookworm) |
| debian | ansible | < ansible 2.9.13+dfsg-1 (bookworm) | ansible 2.9.13+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_ansible_2.9.18-1_on_cbl_mariner_1.0 | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | <= 2.7.16 | — |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.13+dfsg-1 | 2.9.13+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat7.8HIGH
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ansible vulnerabilities
vendor_ubuntu·2022-06-07·CVSS 5.0
CVE-2020-10744 [MEDIUM] Ansible vulnerabilities
Title: Ansible vulnerabilities
Summary: Several security issues were fixed in Ansible.
It was discovered that Ansible did not properly manage directory
permissions when running playbooks with an unprivileged become user. A
local attacker could possibly use this issue to cause a race condition,
escalate privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-1733)
It was discovered that the fix to address CVE-2020-1733 in Ansible was
incomplete on systems using ACLs and FUSE filesystems. A local attacker
could possibly use this issue to cause a race condition, escalate
privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-10744)
It was d
Red Hat
ansible: incomplete fix for CVE-2020-1733
vendor_redhat·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CWE-377 ansible: incomplete fix for CVE-2020-1733
ansible: incomplete fix for CVE-2020-1733
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
An incomplete fix was found for the fix of the flaw CVE-2020-1733, Ansible: insecure temporary directory when running become_user from the become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems.
Statement: Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as pr
Microsoft
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the
vendor_msrc·2020-05-12·CVSS 5.0
CVE-2020-10744 [MEDIUM] CWE-362 An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18 2.8.12 and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5 3.5.6 and 3.6.4 as well as previous versions are affected.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compos
Red Hat
ansible: insecure temporary directory when running become_user from become directive
vendor_redhat·2020-02-18·CVSS 5.0
CVE-2020-1733 [MEDIUM] CWE-377 ansible: insecure temporary directory when running become_user from become directive
ansible: insecure temporary directory when running become_user from become directive
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc//cmdline'.
A race condition flaw was found in Ansible Engine when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the t
Debian
CVE-2020-1733: ansible - A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and pr...
vendor_debian·2020·CVSS 5.0
CVE-2020-1733 [MEDIUM] CVE-2020-1733: ansible - A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and pr...
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc//cmdline'.
Scope: local
bookworm: resolved (fixed in 2.9.7+dfsg-1)
bullseye: resolved (fixed in 2.9.7+dfsg-1)
forky: resolved (fixed in 2.9.7+dfsg-1)
sid: resolved (fixed in 2.9.7+dfsg-1)
trixie: resolved (fixed in 2.9.7+dfsg-1)
Debian
CVE-2020-10744: ansible - An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insec...
vendor_debian·2020·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744: ansible - An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insec...
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
Scope: local
bookworm: resolved (fixed in 2.9.13+dfsg-1)
bullseye: resolved (fixed in 2.9.13+dfsg-1)
forky: resolved (fixed in 2.9.13+dfsg-1)
sid: resolved (fixed in 2.9.13+dfsg-1)
trixie: resolved (fixed in 2.9.13+dfsg-1)
OSV
ansible vulnerabilities
osv·2022-06-07·CVSS 5.0
CVE-2020-1733 [MEDIUM] ansible vulnerabilities
ansible vulnerabilities
It was discovered that Ansible did not properly manage directory
permissions when running playbooks with an unprivileged become user. A
local attacker could possibly use this issue to cause a race condition,
escalate privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-1733)
It was discovered that the fix to address CVE-2020-1733 in Ansible was
incomplete on systems using ACLs and FUSE filesystems. A local attacker
could possibly use this issue to cause a race condition, escalate
privileges and execute arbitrary code. This issue only affected
Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-10744)
It was discovered that Ansible did not properly manage multi-line YAML
s
OSV
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
osv·2022-02-09·CVSS 5.0
CVE-2020-10744 [MEDIUM] Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
GHSA
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
ghsa·2022-02-09·CVSS 5.0
CVE-2020-10744 [MEDIUM] CWE-362 Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
GHSA
Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File
ghsa·2021-04-20
CVE-2020-1733 [LOW] CWE-362 Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File
Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc//cmdline'.
OSV
Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File
osv·2021-04-20
CVE-2020-1733 [LOW] Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File
Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary File
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc//cmdline'.
OSV
CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
osv·2020-05-15·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.
OSV
CVE-2020-1733: A race condition flaw was found in Ansible Engine 2
osv·2020-03-11·CVSS 5.0
CVE-2020-1733 [MEDIUM] CVE-2020-1733: A race condition flaw was found in Ansible Engine 2
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc//cmdline'.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [fedora-all]
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [fedora-all]
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [openstack-rdo]
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [openstack-rdo]
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
RDO includes openstack-ansible-core-2.14.
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733
This flaw refers to the incomplete fix for CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. This vulnerability seems not mitigated fully as there race condition from the original flaw could still happen on systems using ACLs and FUSE filesystems. The 'mkdir -p' is insecure by design.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Mitigation:
Currently, there is no mitigation for this issue.
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1835854]
Affects: fedora-all [bug 1835855]
Affects: openstack-rdo [bug 1835856]
---
Borja, has tis incomplete fix already been reported upstream?
---
In reply
Bugzilla
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [epel-all]
bugzilla·2020-05-14·CVSS 5.0
CVE-2020-10744 [MEDIUM] CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [epel-all]
CVE-2020-10744 ansible: incomplete fix for CVE-2020-1733 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora E
Bugzilla
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [openstack-rdo]
bugzilla·2020-02-27·CVSS 5.0
CVE-2020-1733 [MEDIUM] CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [openstack-rdo]
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [fedora-all]
bugzilla·2020-02-20·CVSS 5.0
CVE-2020-1733 [MEDIUM] CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [fedora-all]
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [epel-all]
bugzilla·2020-02-20·CVSS 5.0
CVE-2020-1733 [MEDIUM] CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [epel-all]
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
bugzilla·2020-02-11·CVSS 5.0
CVE-2020-1733 [MEDIUM] CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive
When a playbook runs a target on a Linux node with an unprivileged become user, a raced condition allows another user on the node to gain control of the become user. In addition, permissions of files owned by the original ssh user on the node can be modified.
When Ansible needs to run a module with become-user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p ", this operation does not fail if the directory already exists and is owned by another user.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1805342]
Affects:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1733https://github.com/ansible/ansible/issues/67791https://lists.debian.org/debian-lts-announce/2020/05/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/https://security.gentoo.org/glsa/202006-11https://www.debian.org/security/2021/dsa-4950https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1733https://github.com/ansible/ansible/issues/67791https://lists.debian.org/debian-lts-announce/2020/05/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/https://security.gentoo.org/glsa/202006-11https://www.debian.org/security/2021/dsa-4950
2020-03-11
Published