An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
CVSS Details
- CVSS 3.1 Base Score: 5.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ansible-baseUpgrade ansible | Oct 1, 2024 | Apr 30, 2020 |
| Amazon Linux Ami 2 | — | Upgrade ansibleUpgrade ansible-doc | Sep 28, 2023 | Apr 30, 2020 |
| Debian | — | Upgrade ansible | Jul 30, 2024 | Apr 30, 2020 |
| Suse | — | Upgrade ansibleUpgrade ansible-docUpgrade ansible-test | Mar 19, 2022 | Apr 30, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 30, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub