Impact
The Ansible FreeBSD Jail Connection Plugin processes transferred files by executing mkdir and mv as root on the host side. These commands follow symbolic links without containment checks, allowing a provider who can create a symlink in the jail to force the host‑side move to write outside the jail. The result is an arbitrary root‑privileged write on the host filesystem, which can be leveraged to install malware, modify system configuration, or compromise SSH keys, effectively granting full host control. This weakness is CWE‑59, representing an insecure path traversal via symlink following.
Affected Systems
Deployments that use the chofstede:ansible_jailexec plugin before version 2.0.0, notably versions up to 1.3.0 and earlier. The vulnerability is triggered when Ansible performs copy, template, fetch or any put_file operation against a FreeBSD jail and the attacker can place a symlink at or above the destination path inside the jail at the time of transfer.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and the vulnerability is not currently listed in the CISA KEV catalog. No EPSS data is available, so the estimated exploitation probability is unknown, but the requirement of host‑side root privileges and the ability to inject arbitrary files make it a high‑risk local privilege escalation scenario. The attack vector is local to the environment that runs the vulnerable plugin; an attacker must control or influence content inside the jail to place the symlink. Once executed, the host can be fully compromised. Because the issue is fixed in v2.0.0, timely patching is essential to mitigate risk.
OpenCVE Enrichment
Github GHSA