Skip to content

Ansible uses a socket with predictable filename in /tmp

Low severity GitHub Reviewed Published May 14, 2022 to the GitHub Advisory Database • Updated Aug 28, 2023

Package

pip Ansible (pip)

Affected versions

< 1.2.3

Patched versions

1.2.3

Description

runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ssh session via a symlink attack on a socket file with a predictable name in /tmp/.

References

Published by the National Vulnerability Database Sep 16, 2013
Published to the GitHub Advisory Database May 14, 2022
Last updated Aug 28, 2023
Reviewed Aug 28, 2023

Severity

Low

Weaknesses

CVE ID

CVE-2013-4259

GHSA ID

GHSA-fj24-ghp9-39v3

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.