漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw allows an attacker to pre-create the directory, resulting in reading private information or forcing ansible-runner to write files as the legitimate user in a place they did not expect. The highest threat from this vulnerability is to confidentiality and integrity.
CVSS Information
N/A
Vulnerability Type
缺省权限不正确
Vulnerability Title
Ansible Runner 安全漏洞
Vulnerability Description
Ansible Runner是Ansible开源的一个工具和 python 库。可在直接与 Ansible 交互或作为另一个系统的一部分时提供帮助。 Ansible Runner 2.0.0版本存在安全漏洞,该漏洞源于默认临时文件配置被写入世界 R/W 位置,攻击者利用该漏洞可以创建目录,从而读取私有信息或强制 ansible-runner 以合法用户的身份将文件写入他们未预料到的位置。
CVSS Information
N/A
Vulnerability Type
N/A