• CVE-2024-9902

发布时间: 2024年12月6日

修改时间: 2024年12月6日

概要

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing the exploited target file, they retain full control over the contents of the file as its owner.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Local
CVSS评分 N/A 6.3
Attack Complexity High
Privileges Required Low
Scope Unchanged
Integrity High
User Interaction Required
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4384 ansible security update 2024年12月30日

影响产品

产品 状态
KY3.5.2 ansible Fixed
V6 ansible Fixed
KY3.5.3 ansible Fixed