ansible is a simple IT automation system.
Affected versions of this package are vulnerable to Information Exposure.
When a user executes
ansible-vault edit, another user on the same computer can read the old and new secret, as it is created in a temporary file with
mkstemp and the returned file descriptor is closed and the method
write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely.
There is no fixed version for