Lack of data validation - Path Traversal In ansible
Description
Ansible symlink attack vulnerability An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 8.5.0 | ||
debian 11 | 2.10.7+merged+base+2.10.17+dfsg-0+deb11u1 | ||
debian 12 | 5.4.0-1 | ||
debian 13 | 5.4.0-1 | ||
debian 14 | 5.4.0-1 | ||
debian 12 | 2.14.16-0+deb12u1 | ||
debian 13 | 2.14.11-1 | ||
debian 14 | 2.14.11-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3.