CVE-2020-10691

MEDIUM5.2EPSS 0.13%

Path Traversal in Ansible

Published: 4/20/2021Modified: 9/4/2024
Also known as:GHSA-3c67-gc48-983wALPINE-CVE-2020-10691DEBIAN-CVE-2020-10691PYSEC-2020-2

Description

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running `ansible-galaxy collection` install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM5.2CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

References (9)