Impact
The vulnerability exposes an insecure extraction routine within ansible‑runner’s unstream_dir() function. When the component processes a streamed ZIP archive provided by a worker, it recreates symbolic links and applies file permissions based on identical archive member names without validating the link target or sanitizing the resulting file path. A crafted archive can therefore create files, symlinks, or modify permissions at locations outside the intended target directory. This path traversal and symlink escape capability enables an attacker to write arbitrary files or alter system files, which can ultimately lead to execution of malicious code on the machine hosting the ansible‑runner worker.
Affected Systems
The flaw affects any installation that includes Red Hat Ansible Automation Platform 2, specifically the ansible‑runner component. No specific sub‑versions are listed, so all deployments that rely on this product are potentially impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity risk. The EPSS score is unavailable and the vulnerability is not present in the CISA KEV catalog, suggesting that exploit activity is currently limited. The likely attack vector involves an attacker who can supply a crafted ZIP archive to an ansible‑runner worker over the transmit/worker protocol; the worker then extracts the archive with its operating system privileges. Successful exploitation can result in arbitrary file creation or permission changes that may give the attacker a foothold for code execution on the host.
OpenCVE Enrichment