CVE-2020-10691

Description

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Risk Information

Base Score
5.2
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
EPSS Score
Exploitation Probability
0.098

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-ansible 2.9.7Windows
Multiple vulnerabilities are affected in Python-ansible 2.9.6Windows
Multiple vulnerabilities are fixed in Python-ansible for linux 2.9.7Linux
Multiple vulnerabilities are affected in Python-ansible for linux 2.9.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234