First published: Wed Mar 25 2020(Updated: )
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running `ansible-galaxy collection` install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Engine | >=2.9.0<2.9.7 | |
Redhat Ansible Tower | =3.0 | |
redhat/ansible-engine | <2.9.7 | 2.9.7 |
pip/ansible | >=2.9.0a1<2.9.7 | 2.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10691 is a vulnerability in all ansible-engine versions 2.9.x prior to 2.9.7 when running `ansible-galaxy collection` install.
CVE-2020-10691 allows an attacker to overwrite any file within the system by exploiting an archive traversal flaw in the directory creation process during the extraction of a collection .tar.gz file.
CVE-2020-10691 has a severity score of 5.2, which is considered medium.
All ansible-engine versions 2.9.x prior to 2.9.7 are affected by CVE-2020-10691.
To fix CVE-2020-10691, upgrade to ansible-engine version 2.9.7 or later.