A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ansibleUpgrade ansible-base | Sep 23, 2020 | Mar 9, 2020 |
| Debian | — | Upgrade ansible | Jul 30, 2024 | Mar 9, 2020 |
| Freebsd | — | Upgrade ansible27Upgrade ansible25Upgrade ansible23Upgrade ansibleUpgrade ansible24Upgrade ansible26 | Apr 18, 2020 | Apr 17, 2020 |
| Gentoo Linux | — | Upgrade app-admin/ansible. | Jun 15, 2020 | Mar 9, 2020 |
| Suse | — | Upgrade ansibleUpgrade ansible-docUpgrade ansible-test | Mar 19, 2022 | Mar 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub