Description
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0011 | An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system. |
Github GHSA |
GHSA-3c67-gc48-983w | Path Traversal in Ansible |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T11:06:11.130Z
Reserved: 2020-03-20T00:00:00.000Z
Link: CVE-2020-10691
No data.
Status : Modified
Published: 2020-04-30T17:15:11.957
Modified: 2024-11-21T04:55:51.900
Link: CVE-2020-10691
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA