Логотип exploitDog
bind:CVE-2020-1737
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1737

Количество 7

Количество 7

ubuntu логотип

CVE-2020-1737

почти 6 лет назад

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-1737

почти 6 лет назад

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-1737

почти 6 лет назад

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-1737

почти 6 лет назад

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9 ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-893h-35v4-mxqx

почти 5 лет назад

Path Traversal in Ansible

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2020-05681

почти 6 лет назад

Уязвимость модуля win_unzip системы управления конфигурациями Ansible, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0081-1

почти 4 года назад

Security update for ansible

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-1737

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-1737

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-1737

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-1737

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9 ...

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
github логотип
GHSA-893h-35v4-mxqx

Path Traversal in Ansible

CVSS3: 7.8
0%
Низкий
почти 5 лет назад
fstec логотип
BDU:2020-05681

Уязвимость модуля win_unzip системы управления конфигурациями Ansible, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0081-1

Security update for ansible

почти 4 года назад

Уязвимостей на страницу