QID 995981
Date Published: 2023-11-20
QID 995981: Python (Pip) Security Update for galaxy-importer (GHSA-55g2-vm3q-7w52)
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-55g2-vm3q-7w52 for updates and patch information.
Vendor References
- GHSA-55g2-vm3q-7w52 -
github.com/advisories/GHSA-55g2-vm3q-7w52
CVEs related to QID 995981
Software Advisories
| Advisory ID | Software | Component | Link |
|---|