CVE-2023-5189: Hub: insecure galaxy-importer tarfile extraction
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
Other sources
A vulnerability was found in the galaxy importer of Ansible Automation Hub. The tarball extraction code is open to abuse in several ways (relative paths in the middle of a path, as well as symlinks that target arbitrary paths). If used to extract user-provided tarballs, this flaw could lead to arbitrary file overwrite.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5189?
CVE-2023-5189 is a path traversal vulnerability that exists in Ansible when extracting tarballs.
How does CVE-2023-5189 affect Ansible Automation Hub?
When using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
What is the severity of CVE-2023-5189?
CVE-2023-5189 has a severity rating of medium with a CVSS score of 6.3.
Which software packages are affected by CVE-2023-5189?
The affected software includes the galaxy-importer package (version up to and inclusive 0.4.16), Redhat Ansible Automation Platform (version 2.0), and Redhat Satellite (version 6.0).
How can I fix CVE-2023-5189?
To fix CVE-2023-5189, update to a version of the affected software that includes the necessary security patch.