CVE-2020-10691
30.04.2020, 17:15
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Vendor | Product | Version |
---|---|---|
redhat | ansible_engine | 2.9.0 ≤ 𝑥 < 2.9.7 |
redhat | ansible_tower | 3.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases