Junglewise Threat Intelligence

PYSEC-2021-125 - A flaw was found in Ansible where the secret information present in async_files are getting disclosed when the user changes the jobdir to a

Severity: info · Published 2021-06-09

Technologies: ansible (PyPI). Vendors: PyPI.

Executive brief

A flaw was found in Ansible where the secret information present in async_files are getting disclosed when the user changes the jobdir to a world readable directory. Any secret information in an async status file will be readable by a malicious user on that system. This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.

Affected products

  • PyPI ansible

Related threats