An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
2020-04-30T17:15:11.957
2024-11-21T04:55:51.900
Modified
CVSSv3.1: 5.2 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:P/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible_engine | < 2.9.7 | Yes |
Application | redhat | ansible_tower | 3.0 | Yes |