Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10691

Опубликовано: 27 мар. 2020
Источник: redhat
CVSS3: 5.2

Описание

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

An archive traversal flaw was found in Ansible Engine when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Отчет

Ansible Engine 2.9.6 as well as previous 2.9.x versions are affected. Ansible versions less than or equal to 2.8 are not affected by this vulnerability as this functionality was introduced on 2.9. Ansible Tower 3.6.3 as well as previous 3.6.x versions are affected as they use ansible-galaxy collections.

Меры по смягчению последствий

A possible mitigation of archive traversal issue could be done by restricting file access control and directory write accesses for extracting tarball files. This is feasible only for scenarios when the destination path could be known and enforced beforehand.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2ansibleNot affected
Red Hat Ceph Storage 3ansibleNot affected
Red Hat OpenStack Platform 10 (Newton)ansibleNot affected
Red Hat OpenStack Platform 13 (Queens)ansibleNot affected
Red Hat Storage 3ansibleNot affected
Red Hat Ansible Engine 2.9 for RHEL 7ansibleFixedRHSA-2020:154122.04.2020
Red Hat Ansible Engine 2.9 for RHEL 8ansibleFixedRHSA-2020:154122.04.2020
Red Hat Ansible Engine 2 for RHEL 7ansibleFixedRHSA-2020:154222.04.2020
Red Hat Ansible Engine 2 for RHEL 8ansibleFixedRHSA-2020:154222.04.2020
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHBA-2020:154022.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1817161Ansible: archive traversal vulnerability in ansible-galaxy collection install

5.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.2
ubuntu
почти 6 лет назад

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

CVSS3: 5.2
nvd
почти 6 лет назад

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

CVSS3: 5.2
debian
почти 6 лет назад

An archive traversal flaw was found in all ansible-engine versions 2.9 ...

CVSS3: 5.2
github
почти 5 лет назад

Path Traversal in Ansible

suse-cvrf
почти 4 года назад

Security update for ansible

5.2 Medium

CVSS3