REDHAT-BUG-2544510: Path Traversal
Reported via the ansible-security list by Liqiang Ji (ISCAS / SQUARE Research Group).
Module: src/ansiblerunner/utils/streaming.py, function unstreamdir().
unstreamdir() performs a custom ("fancy") extraction to preserve permissions and symlinks. Two defects: 1. CWE-59 (link following): a symlink member's target is read verbatim from the archive content and re-created with os.symlink() without validation, so it can point outside targetdirectory (e.g. '../outside' or an absolute path). A subsequent member extracted through that symlink lands outside targetdirectory (arbitrary write escape). 2. CWE-22 (path traversal): outpath = os.path.join(targetdirectory, info.filename) is built from the unsanitized member name. ZipFile.extract() sanitizes the arcname, but os.utime()/os.chmod() operate on the raw outpath, so a member named '../victim' changes mtime/permissions on a file outside targetdirectory.
Exploitability: in the standard AWX/AAP topology the transmit stream is produced by the trusted controller (streamdir only encodes pre-existing symlinks) and the controller->executor path is authenticated, so there this is defense-in-depth hardening. It is directly relevant to deployments that feed untrusted input into ansible-runner's Worker() path.
Upstream: https://github.com/ansible/ansible-runner Fix PR: https://github.com/ansible/ansible-runner/pull/1550 Confirmed present in 2.4.3 and devel.
Affected Software
Event History
Frequently Asked Questions
Which deployments are most exposed?
Deployments where an untrusted party can supply or influence the transmit stream are most exposed. In the standard AWX/AAP topology, the stream is produced by a trusted controller and the controller-to-executor path is authenticated, so the issue is described as defense-in-depth hardening there.
What does an attacker need to exploit this?
An attacker needs control over archive member names or symlink targets in the stream processed by unstream_dir(). A crafted symlink can redirect later extraction outside the target directory, while a crafted traversal name can cause timestamp or permission changes on an external path.
What can be done before an update is available?
Restrict stream generation to trusted controllers and maintain authentication on the controller-to-executor path. Do not allow untrusted users or systems to provide or modify streams processed by the affected extraction routine.