CVE-2020-1737
Summary
| CVE | CVE-2020-1737 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-09 16:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: ansible-2.9.6-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Ansible: Multiple vulnerabilities (GLSA 202006-11) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 30 Update: ansible-2.9.6-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 30 Update: ansible-2.9.6-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: ansible-2.9.6-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: ansible-2.9.6-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 1802154 – (CVE-2020-1737) CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Vendor Advisory |
| win_unzip path traversal with specially crafted archive · Issue #67795 · ansible/ansible · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: ansible-2.9.6-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500009 Alpine Linux Security Update for ansible
- 501349 Alpine Linux Security Update for ansible-base
- 982730 Python (pip) Security Update for ansible (GHSA-893h-35v4-mxqx)