Vulnerabilities > Redhat > Ansible Runner > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-08-23 CVE-2021-3701 Incorrect Default Permissions vulnerability in Redhat Ansible Runner 2.0.0
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations.
local
low complexity
redhat CWE-276
6.6
2022-08-23 CVE-2021-3702 Race Condition vulnerability in Redhat Ansible Runner 2.0.0
A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute their directory at that name, and then have access to ansible-runner's private_data_dir the next time ansible-runner made use of the private_data_dir.
local
high complexity
redhat CWE-362
6.3