Description
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4396-1 | ansible security update |
EUVD |
EUVD-2019-0009 | Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path. |
Github GHSA |
GHSA-74vq-h4q8-x6jv | Ansible Path Traversal vulnerability |
Ubuntu USN |
USN-4072-1 | Ansible vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:19:18.580Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3828
No data.
Status : Modified
Published: 2019-03-27T13:29:01.617
Modified: 2024-11-21T04:42:37.820
Link: CVE-2019-3828
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA
Ubuntu USN