Safety vulnerability ID: 74221
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Ansible are vulnerable to Incorrect Authorization (CWE-863). This flaw allows unprivileged users to silently create or replace any file on the system and assume ownership when a privileged user executes the user module against the unprivileged user's home directory. The attack requires the attacker to have traversal permissions on the directory containing the target file. To exploit, an attacker leverages these permissions to manipulate file contents.
Latest version: 2.19.2
Radically simple IT automation
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application