Debian Ansible-Runner vulnerabilities
2 known vulnerabilities affecting debian/ansible-runner.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-4041P3HIGHCVSS 7.8fixed in ansible-runner 2.1.1-1 (bookworm)2021
CVE-2021-4041 [HIGH] CVE-2021-4041: ansible-runner - A flaw was found in ansible-runner. An improper escaping of the shell command, w...
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
debian
CVE-2021-3701P4MEDIUMCVSS 6.6fixed in ansible-runner 2.1.1-1 (bookworm)2021
CVE-2021-3701 [MEDIUM] CVE-2021-3701: ansible-runner - A flaw was found in ansible-runner where the default temporary files configurati...
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this v
debian