CVE-2020-10691: Path Traversal

Published Mar 25, 2020
·
Updated

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Other sources

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

MITRE

ansible-galaxy collection install has a archive traversal vulnerability when extracing a collection .tar.gz file, neither install() nor the called extracttarfile() does any sanitizing on the filename. This should allow a specially crafted collection .tar.gz file to place a file wherever it wants in the file system.

Red Hat

Affected Software

4 affected componentsFixes available
redhat/ansible-engine<2.9.7
2.9.7
pip/ansible>=2.9.0a1<2.9.7
2.9.7
redhat Ansible Engine>=2.9.0<2.9.7
redhat Ansible Tower=3.0

Event History

Apr 30, 2020
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionSeverityWeakness
Apr 20, 2021
Advisory Published
04:44 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-10691?

CVE-2020-10691 is a vulnerability in all ansible-engine versions 2.9.x prior to 2.9.7 when running `ansible-galaxy collection` install.

2

How does CVE-2020-10691 work?

CVE-2020-10691 allows an attacker to overwrite any file within the system by exploiting an archive traversal flaw in the directory creation process during the extraction of a collection .tar.gz file.

3

What is the severity of CVE-2020-10691?

CVE-2020-10691 has a severity score of 5.2, which is considered medium.

4

Which versions of ansible-engine are affected by CVE-2020-10691?

All ansible-engine versions 2.9.x prior to 2.9.7 are affected by CVE-2020-10691.

5

How can I fix CVE-2020-10691?

To fix CVE-2020-10691, upgrade to ansible-engine version 2.9.7 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203