CVE-2024-9902 is a medium-severity vulnerability in ansible-core's user module, allowing an unprivileged user to silently create or replace arbitrary files and take ownership when a privileged user executes the module against their home directory. The attack requires low privileges and user interaction, with high impact on confidentiality and integrity, and low impact on availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.4 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Ansible Automation Platform 2.4 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Ansible Automation Platform 2.5 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenStack Platform 17.1 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Ansible-core: ansible-core user may read/write unauthorized content
Nov 12, 2024ansible-core Incorrect Authorization vulnerability
Nov 6, 2024ansible-core: Ansible-core user may read/write unauthorized content
Nov 6, 2024