A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
2020-03-16T16:15:13.890
2024-11-21T05:11:16.333
Modified
CVSSv3.1: 4.2 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | ansible | < 2.7.17 | Yes |
| Application | redhat | ansible | < 2.8.11 | Yes |
| Application | redhat | ansible | < 2.9.7 | Yes |
| Application | redhat | ansible_tower | ≤ 3.3.4 | Yes |
| Application | redhat | ansible_tower | ≤ 3.4.5 | Yes |
| Application | redhat | ansible_tower | ≤ 3.5.5 | Yes |
| Application | redhat | ansible_tower | ≤ 3.6.3 | Yes |
| Application | redhat | cloudforms_management_engine | 5.0 | Yes |
| Application | redhat | openstack | 13 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |
| Operating System | fedoraproject | fedora | 30 | Yes |
| Operating System | fedoraproject | fedora | 31 | Yes |
| Operating System | fedoraproject | fedora | 32 | Yes |