QID 996474
Date Published: 2024-01-04
QID 996474: Python (Pip) Security Update for ansible (GHSA-jpvw-p8pr-9g2x)
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-jpvw-p8pr-9g2x for updates and patch information.
Vendor References
- GHSA-jpvw-p8pr-9g2x -
github.com/advisories/GHSA-jpvw-p8pr-9g2x
CVEs related to QID 996474
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jpvw-p8pr-9g2x | ansible |
|