QID 981243

QID 981243: Python (pip) Security Update for ansible (GHSA-74vq-h4q8-x6jv)

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution
    Customers are advised to refer to GHSA-74vq-h4q8-x6jv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981243

    Software Advisories
    Advisory ID Software Component Link
    GHSA-74vq-h4q8-x6jv ansible URL Logo github.com/advisories/GHSA-74vq-h4q8-x6jv