Race condition in Red Hat Ansible Engine - CVE-2020-1733

 

Race condition in Red Hat Ansible Engine - CVE-2020-1733

Published: June 15, 2020


Vulnerability identifier: #VU29023
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1733
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition when running a playbook with an unprivileged become user. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

Red Hat Ansible Engine
Gentoo Linux
Fedora
ansible (Debian package)
ansible (Alpine package)
ansible
ansible (Red Hat package)
Ansible

How to mitigate CVE-2020-1733

Install updates from vendor's website.

Red Hat Ansible Engine - addressed in versions 2.7.17, 2.8.11, 2.9.7
ansible (Debian package) - update to 2.7.7+dfsg-1+deb10u1
ansible (Alpine package) - update to 2.7.17-r0
Ansible - addressed in versions 2.7.17-1.el7ae, 2.8.11-1.el7ae, 2.8.11-1.el8ae, 2.9.7-1.el7ae, 2.9.7-1.el8ae
ansible - addressed in versions 2.9.7-1.el7, 2.9.7-1.el8, 2.9.7-1.fc30, 2.9.7-1.fc31, 2.9.7-1.fc32
ansible (Red Hat package) - addressed in versions 2.9.7-1.el7ae, 2.9.7-1.el8ae

External References

Related Security Bulletins