CVE-2020-10691

MEDIUM5.2EPSS 0.13%

Path Traversal in Ansible

發布日:2021/4/20修改日:2024/9/4
也稱為:GHSA-3c67-gc48-983wALPINE-CVE-2020-10691DEBIAN-CVE-2020-10691PYSEC-2020-2

描述

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running `ansible-galaxy collection` install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM5.2CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

參考連結(9)