CVE-2019-3828: Path Traversal
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
Other sources
Ansible fetch module has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3828?
CVE-2019-3828 is a path traversal vulnerability in the Ansible fetch module before versions 2.5.15, 2.6.14, and 2.7.8.
How does CVE-2019-3828 affect Ansible?
CVE-2019-3828 allows an attacker to copy and overwrite files outside of the specified destination in the local Ansible controller host.
What is the severity of CVE-2019-3828?
The severity of CVE-2019-3828 is medium with a CVSS score of 4.2.
How can I fix CVE-2019-3828 in Ansible?
To fix CVE-2019-3828 in Ansible, upgrade to version 2.5.15, 2.6.14, or 2.7.8.
Where can I find more information about CVE-2019-3828?
More information about CVE-2019-3828 can be found on the NVD (National Vulnerability Database) and GitHub.