A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
2023-11-14T23:15:12.290
2024-12-06T11:15:07.380
Modified
CVSSv3.1: 6.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | ansible_automation_platform | 2.0 | Yes |
| Application | redhat | satellite | 6.0 | Yes |