py-ansible -- data leak vulnerability
Tapas jena reports:
A flaw was found in Ansible where the secret information present in async_files are getting disclosed when the user changes the jobdir to a world readable directory.
Any secret information in an async status file will be readable by a malicious user on that system.
This flaw affects Ansible Tower 3.7 and Ansible Automation Platform 1.2.
Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright