ZeroHour

CVE-2020-10691

CVSS 3.1
5.2 medium
EPSS
<1%p29
Published
()
Modified
Description

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Vendors
redhat
Products
ansible engine, ansible tower
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.