Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
CVSS Details
- CVSS 3.1 Base Score: 4.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-ansiblealpine-linux-upgrade-ansible-base | Dec 12, 2019 | Mar 27, 2019 | |
| Debian | debian-upgrade-ansible | Feb 20, 2019 | Feb 19, 2019 | |
| Suse | — | suse-upgrade-ansible | Apr 3, 2019 | Mar 27, 2019 |
| Ubuntu | ubuntu-upgrade-ansible | Jul 25, 2019 | Mar 27, 2019 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Mar 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub