ZeroHour

CVE-2019-3828

CVSS 3.1
4.2 medium
EPSS
<1%p43
Published
()
Modified
Description

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

Vendors
redhat
Products
ansible
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.