Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5115

Опубликовано: 18 дек. 2023
Источник: debian
EPSS Низкий

Описание

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansible-corefixed2.14.11-1package
ansible-corefixed2.14.16-0+deb12u1bookwormpackage
ansible-coreno-dsabullseyepackage
ansiblefixed5.4.0-1package
ansiblefixed2.10.7+merged+base+2.10.17+dfsg-0+deb11u1bullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2233810

  • https://github.com/ansible/ansible/pull/81780

  • https://github.com/ansible/ansible/commit/ddf0311c63287e2d5334770377350c1e0cbfff28

  • ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid

EPSS

Процентиль: 56%
0.00346
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

CVSS3: 6.3
redhat
почти 2 года назад

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

CVSS3: 6.3
nvd
больше 1 года назад

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

CVSS3: 6.3
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 6.3
github
больше 1 года назад

Ansible symlink attack vulnerability

EPSS

Процентиль: 56%
0.00346
Низкий