QID 982729

QID 982729: Python (pip) Security Update for ansible (GHSA-3c67-gc48-983w)

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.2 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution
    Customers are advised to refer to GHSA-3c67-gc48-983w for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982729

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3c67-gc48-983w ansible URL Logo github.com/advisories/GHSA-3c67-gc48-983w