CVE-2019-3828

Description

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

Risk Information

Base Score
4.2
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.03

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-3828 are fixed in Python-ansible 2.5.15Windows
Vulnerabilities CVE-2019-3828 are fixed in Python-ansible 2.6.14Windows
Vulnerabilities CVE-2019-3828 are fixed in Python-ansible 2.7.8Windows
ansible security update(DSA-4396-1) ansible_2.2.1.0-2+deb9u1_all.debLinux
Configuration management, deployment, and task execution system (USN-4072-1) ansible_2.0.0.2-2ubuntu1.3_all.debLinux
Configuration management, deployment, and task execution system (USN-4072-1) ansible_2.5.1+dfsg-1ubuntu0.1_all.debLinux
Configuration management, deployment, and task execution system (USN-4072-1) ansible_2.7.8+dfsg-1ubuntu0.19.04.1_all.debLinux
Vulnerabilities CVE-2019-3828 are fixed in Python-ansible for linux 2.5.15Linux
Vulnerabilities CVE-2019-3828 are fixed in Python-ansible for linux 2.6.14Linux
Vulnerabilities CVE-2019-3828 are fixed in Python-ansible for linux 2.7.8Linux
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability (CVE-2019-3828)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234