CVE-2024-9902
published 2024-11-06CVE-2024-9902: A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system…
PriorityP431medium6.3CVSS 3.1
AVLACHPRLUIRSUCHIHAL
EPSS
0.26%
17.0th percentile
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| debian | ansible-core | < ansible 5.4.0-1 (bookworm) | ansible 5.4.0-1 (bookworm) |
| msrc | azl3_ansible_2.17.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ansible_2.17.11-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_ansible_2.14.12-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_ansible_2.14.18-1_on_cbl_mariner_2.0 | — | — |
| redhat | ansible | >= 0 < 2.10.7+merged+base+2.10.17+dfsg-0+deb11u2 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u2 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
| redhat | ansible | >= 0 < 5.4.0-1 | 5.4.0-1 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_msrc6.3MEDIUM
vendor_oracle6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (Ansible) — CVE-2024-9902
vendor_oracle·2025-04-15·CVSS 6.3
CVE-2024-9902 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (Ansible) — CVE-2024-9902
Oracle Oracle Siebel CRM Risk Matrix: Siebel Cloud Manager (Ansible) vulnerability
CVE: CVE-2024-9902
CVSS: 6.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2025 (APR 2025)
Microsoft
Ansible-core: ansible-core user may read/write unauthorized content
vendor_msrc·2024-11-12·CVSS 6.3
CVE-2024-9902 [MEDIUM] CWE-863 Ansible-core: ansible-core user may read/write unauthorized content
Ansible-core: ansible-core user may read/write unauthorized content
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference:
Red Hat
ansible-core: Ansible-core user may read/write unauthorized content
vendor_redhat·2024-11-06·CVSS 6.3
CVE-2024-9902 [MEDIUM] CWE-863 ansible-core: Ansible-core user may read/write unauthorized content
ansible-core: Ansible-core user may read/write unauthorized content
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged us
Debian
CVE-2024-9902: ansible - A flaw was found in Ansible. The ansible-core `user` module can allow an unprivi...
vendor_debian·2024·CVSS 6.3
CVE-2024-9902 [MEDIUM] CVE-2024-9902: ansible - A flaw was found in Ansible. The ansible-core `user` module can allow an unprivi...
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
Scope: local
bookworm: resolved (fixed in 5.4.0-1)
bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+deb11u2)
forky: resolved (fixed in 5.4.0-1)
sid: resolved (fixed in 5.4.0-1)
trixie: resolved (fixed in 5.4.0-1)
OSV
CVE-2024-9902: A flaw was found in Ansible
osv·2024-11-06·CVSS 6.3
CVE-2024-9902 [MEDIUM] CVE-2024-9902: A flaw was found in Ansible
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
OSV
ansible-core Incorrect Authorization vulnerability
osv·2024-11-06
CVE-2024-9902 [MEDIUM] ansible-core Incorrect Authorization vulnerability
ansible-core Incorrect Authorization vulnerability
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
GHSA
ansible-core Incorrect Authorization vulnerability
ghsa·2024-11-06
CVE-2024-9902 [MEDIUM] CWE-863 ansible-core Incorrect Authorization vulnerability
ansible-core Incorrect Authorization vulnerability
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:10762https://access.redhat.com/errata/RHSA-2024:8969https://access.redhat.com/errata/RHSA-2024:9894https://access.redhat.com/errata/RHSA-2025:1861https://access.redhat.com/security/cve/CVE-2024-9902https://bugzilla.redhat.com/show_bug.cgi?id=2318271https://lists.debian.org/debian-lts-announce/2024/11/msg00021.html
2024-11-06
Published