QID 980882
QID 980882: Python (pip) Security Update for ansible (GHSA-rh6x-qvg7-rrmj)
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rh6x-qvg7-rrmj for updates pertaining to this vulnerability.
Vendor References
- GHSA-rh6x-qvg7-rrmj -
github.com/advisories/GHSA-rh6x-qvg7-rrmj
CVEs related to QID 980882
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rh6x-qvg7-rrmj | ansible |
|