First published: Wed Nov 15 2023(Updated: )
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
Affected Software | Affected Version | How to fix |
---|---|---|
pip/galaxy-importer | <=0.4.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is GHSA-55g2-vm3q-7w52.
The title of the vulnerability is 'A path traversal vulnerability exists in Ansible when extracting tarballs.'
The affected software is pip/galaxy-importer version 0.4.16.
The severity of the vulnerability is medium with a CVSS score of 6.3.
An attacker can exploit this vulnerability by crafting a malicious tarball that drops a symlink on the disk when using the galaxy importer of Ansible Automation Hub, resulting in file overwrites.