cbcvebase.
CVE-2021-3533
published 2021-06-09

CVE-2021-3533: A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world writable directory. When this occurs, there is a race…

medium6.5
A flaw was found in Ansible if an ansible user sets ANSIBLE_ASYNC_DIR to a subdirectory of a world writable directory. When this occurs, there is a race condition on the managed machine. A malicious, non-privileged account on the remote machine can exploit the race condition to access the async result data. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.

Affected

3 ranges
VendorProductVersion rangeFixed in
libbpf_projectlibbpf>= 0 < 0.5.0-1ubuntu22.04.10.5.0-1ubuntu22.04.1
libbpf_projectlibbpf>= 0 < 0.5.0-1~ubuntu20.04.1+esm10.5.0-1~ubuntu20.04.1+esm1
redhatansible>= 0 < 3.0.03.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.