Lack of data validation - Path Traversal In ansible-base
Description
Path Traversal in Ansible
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
alpine v3.14 | =0.3.1-r0 || =0.4-r0 || =0.5-r0 || =0.7-r0 || =0.7.1-r0 || =0.8-r0 || =0.9-r0 || =1.0-r0 || =1.0-r1 || =1.1-r0 || =1.1-r1 || =1.2-r1 || =1.2.1-r1 || =1.2.2-r0 || =1.2.3-r0 || =1.3.3-r0 || =1.3.4-r0 || =1.4.1-r0 || =1.4.3-r0 || =1.4.5-r0 || =1.5.0-r0 || =1.5.4-r0 || =1.5.5-r0 || =1.6.1-r0 || =1.6.5-r0 || =1.6.6-r0 || =1.6.7-r0 || =1.7.0-r0 || =1.7.1-r0 || =1.7.2-r0 || =1.8.0-r0 || =1.8.2-r0 || =1.8.4-r0 || =1.9.2-r0 || =1.9.2-r1 || =1.9.3-r0 || =1.9.3-r1 || =1.9.4-r0 || =2.0.0.2-r0 || =2.0.0.2-r1 || =2.0.1.0-r1 || =2.1.0.0-r0 || =2.1.1.0-r0 || =2.1.2.0-r0 || =2.2.0.0-r0 || =2.2.1.0-r0 || =2.2.1.0-r1 || =2.2.2.0-r0 || =2.3.0.0-r0 || =2.3.0.0-r1 || =2.3.1.0-r0 || =2.3.2.0-r0 || =2.4.0.0-r0 || =2.4.1.0-r0 || =2.4.2.0-r0 || =2.4.3.0-r0 || =2.5.0-r0 || =2.5.2-r0 || =2.5.4-r0 || =2.5.5-r0 || =2.6.0-r0 || =2.6.1-r0 || =2.6.3-r0 || =2.7.0-r0 || =2.7.0-r1 || =2.7.9-r0 || =2.7.9-r1 || =2.8.0-r1 || =2.8.1-r0 || =2.8.2-r0 || =2.8.3-r0 || =2.8.4-r0 || =2.8.6-r0 || =2.8.6-r1 || =2.8.6-r2 || =2.8.6-r3 || =2.9.1-r0 || =2.9.2-r0 || =2.9.2-r1 || =2.9.3-r0 || =2.9.4-r0 || =2.9.5-r0 || =2.9.6-r0 || >=0 <2.9.7-r0 | 2.9.7-r0 | |
debian 12 | >=0 <2.9.7+dfsg-1 | 2.9.7+dfsg-1 | |
alpine v3.11 | =0.3.1-r0 || =0.4-r0 || =0.5-r0 || =0.7-r0 || =0.7.1-r0 || =0.8-r0 || =0.9-r0 || =1.0-r0 || =1.0-r1 || =1.1-r0 || =1.1-r1 || =1.2-r1 || =1.2.1-r1 || =1.2.2-r0 || =1.2.3-r0 || =1.3.3-r0 || =1.3.4-r0 || =1.4.1-r0 || =1.4.3-r0 || =1.4.5-r0 || =1.5.0-r0 || =1.5.4-r0 || =1.5.5-r0 || =1.6.1-r0 || =1.6.5-r0 || =1.6.6-r0 || =1.6.7-r0 || =1.7.0-r0 || =1.7.1-r0 || =1.7.2-r0 || =1.8.0-r0 || =1.8.2-r0 || =1.8.4-r0 || =1.9.2-r0 || =1.9.2-r1 || =1.9.3-r0 || =1.9.3-r1 || =1.9.4-r0 || =2.0.0.2-r0 || =2.0.0.2-r1 || =2.0.1.0-r1 || =2.1.0.0-r0 || =2.1.1.0-r0 || =2.1.2.0-r0 || =2.2.0.0-r0 || =2.2.1.0-r0 || =2.2.1.0-r1 || =2.2.2.0-r0 || =2.3.0.0-r0 || =2.3.0.0-r1 || =2.3.1.0-r0 || =2.3.2.0-r0 || =2.4.0.0-r0 || =2.4.1.0-r0 || =2.4.2.0-r0 || =2.4.3.0-r0 || =2.5.0-r0 || =2.5.2-r0 || =2.5.4-r0 || =2.5.5-r0 || =2.6.0-r0 || =2.6.1-r0 || =2.6.3-r0 || =2.7.0-r0 || =2.7.0-r1 || =2.7.9-r0 || =2.7.9-r1 || =2.8.0-r1 || =2.8.1-r0 || =2.8.2-r0 || =2.8.3-r0 || =2.8.4-r0 || =2.8.6-r0 || =2.8.6-r1 || =2.8.6-r2 || =2.8.6-r3 || =2.9.1-r0 || =2.9.3-r0 || =2.9.6-r0 || >=0 <2.9.7-r0 | 2.9.7-r0 | |
alpine v3.13 | =0.3.1-r0 || =0.4-r0 || =0.5-r0 || =0.7-r0 || =0.7.1-r0 || =0.8-r0 || =0.9-r0 || =1.0-r0 || =1.0-r1 || =1.1-r0 || =1.1-r1 || =1.2-r1 || =1.2.1-r1 || =1.2.2-r0 || =1.2.3-r0 || =1.3.3-r0 || =1.3.4-r0 || =1.4.1-r0 || =1.4.3-r0 || =1.4.5-r0 || =1.5.0-r0 || =1.5.4-r0 || =1.5.5-r0 || =1.6.1-r0 || =1.6.5-r0 || =1.6.6-r0 || =1.6.7-r0 || =1.7.0-r0 || =1.7.1-r0 || =1.7.2-r0 || =1.8.0-r0 || =1.8.2-r0 || =1.8.4-r0 || =1.9.2-r0 || =1.9.2-r1 || =1.9.3-r0 || =1.9.3-r1 || =1.9.4-r0 || =2.0.0.2-r0 || =2.0.0.2-r1 || =2.0.1.0-r1 || =2.1.0.0-r0 || =2.1.1.0-r0 || =2.1.2.0-r0 || =2.2.0.0-r0 || =2.2.1.0-r0 || =2.2.1.0-r1 || =2.2.2.0-r0 || =2.3.0.0-r0 || =2.3.0.0-r1 || =2.3.1.0-r0 || =2.3.2.0-r0 || =2.4.0.0-r0 || =2.4.1.0-r0 || =2.4.2.0-r0 || =2.4.3.0-r0 || =2.5.0-r0 || =2.5.2-r0 || =2.5.4-r0 || =2.5.5-r0 || =2.6.0-r0 || =2.6.1-r0 || =2.6.3-r0 || =2.7.0-r0 || =2.7.0-r1 || =2.7.9-r0 || =2.7.9-r1 || =2.8.0-r1 || =2.8.1-r0 || =2.8.2-r0 || =2.8.3-r0 || =2.8.4-r0 || =2.8.6-r0 || =2.8.6-r1 || =2.8.6-r2 || =2.8.6-r3 || =2.9.1-r0 || =2.9.2-r0 || =2.9.2-r1 || =2.9.3-r0 || =2.9.4-r0 || =2.9.5-r0 || =2.9.6-r0 || >=0 <2.9.7-r0 | 2.9.7-r0 | |
alpine v3.12 | =0.3.1-r0 || =0.4-r0 || =0.5-r0 || =0.7-r0 || =0.7.1-r0 || =0.8-r0 || =0.9-r0 || =1.0-r0 || =1.0-r1 || =1.1-r0 || =1.1-r1 || =1.2-r1 || =1.2.1-r1 || =1.2.2-r0 || =1.2.3-r0 || =1.3.3-r0 || =1.3.4-r0 || =1.4.1-r0 || =1.4.3-r0 || =1.4.5-r0 || =1.5.0-r0 || =1.5.4-r0 || =1.5.5-r0 || =1.6.1-r0 || =1.6.5-r0 || =1.6.6-r0 || =1.6.7-r0 || =1.7.0-r0 || =1.7.1-r0 || =1.7.2-r0 || =1.8.0-r0 || =1.8.2-r0 || =1.8.4-r0 || =1.9.2-r0 || =1.9.2-r1 || =1.9.3-r0 || =1.9.3-r1 || =1.9.4-r0 || =2.0.0.2-r0 || =2.0.0.2-r1 || =2.0.1.0-r1 || =2.1.0.0-r0 || =2.1.1.0-r0 || =2.1.2.0-r0 || =2.2.0.0-r0 || =2.2.1.0-r0 || =2.2.1.0-r1 || =2.2.2.0-r0 || =2.3.0.0-r0 || =2.3.0.0-r1 || =2.3.1.0-r0 || =2.3.2.0-r0 || =2.4.0.0-r0 || =2.4.1.0-r0 || =2.4.2.0-r0 || =2.4.3.0-r0 || =2.5.0-r0 || =2.5.2-r0 || =2.5.4-r0 || =2.5.5-r0 || =2.6.0-r0 || =2.6.1-r0 || =2.6.3-r0 || =2.7.0-r0 || =2.7.0-r1 || =2.7.9-r0 || =2.7.9-r1 || =2.8.0-r1 || =2.8.1-r0 || =2.8.2-r0 || =2.8.3-r0 || =2.8.4-r0 || =2.8.6-r0 || =2.8.6-r1 || =2.8.6-r2 || =2.8.6-r3 || =2.9.1-r0 || =2.9.2-r0 || =2.9.2-r1 || =2.9.3-r0 || =2.9.4-r0 || =2.9.5-r0 || =2.9.6-r0 || >=0 <2.9.7-r0 | 2.9.7-r0 | |
debian 11 | >=0 <2.9.7+dfsg-1 | 2.9.7+dfsg-1 | |
debian 14 | >=0 <2.9.7+dfsg-1 | 2.9.7+dfsg-1 | |
debian 13 | >=0 <2.9.7+dfsg-1 | 2.9.7+dfsg-1 | |
pypi | >=2.9.0a1 <2.9.7 | 2.9.7 |
Aliases
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.