Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpvw-p8pr-9g2x

Опубликовано: 28 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Ansible symlink attack vulnerability

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 8.5.0

8.5.0

EPSS

Процентиль: 56%
0.00346
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-22
CWE-36

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

CVSS3: 6.3
redhat
почти 2 года назад

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

CVSS3: 6.3
nvd
больше 1 года назад

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

CVSS3: 6.3
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 6.3
debian
больше 1 года назад

An absolute path traversal attack exists in the Ansible automation pla ...

EPSS

Процентиль: 56%
0.00346
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-22
CWE-36