Ansible Path Traversal vulnerability
Moderate severity
GitHub Reviewed
Published
Apr 15, 2019
to the GitHub Advisory Database
•
Updated Sep 6, 2024
Package
Affected versions
< 2.5.15
>= 2.6.0a1, < 2.6.14
>= 2.7.0a1, < 2.7.8
Patched versions
2.5.15
2.6.14
2.7.8
Description
Published by the National Vulnerability Database
Mar 27, 2019
Published to the GitHub Advisory Database
Apr 15, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 6, 2024
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
References