Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
CVSS Details
- CVSS 3.1 Base Score: 4.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ansible-baseUpgrade ansible | Dec 12, 2019 | Mar 27, 2019 |
| Debian | — | Upgrade ansible | Feb 20, 2019 | Feb 19, 2019 |
| Suse | — | Upgrade ansible | Apr 3, 2019 | Mar 27, 2019 |
| Ubuntu | — | Upgrade ansible | Jul 25, 2019 | Mar 27, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub