QID 982729
QID 982729: Python (pip) Security Update for ansible (GHSA-3c67-gc48-983w)
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3c67-gc48-983w for updates pertaining to this vulnerability.
Vendor References
- GHSA-3c67-gc48-983w -
github.com/advisories/GHSA-3c67-gc48-983w
CVEs related to QID 982729
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3c67-gc48-983w | ansible |
|