CVE-2020-10691
published 2020-04-30CVE-2020-10691: An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a…
PriorityP422medium5.2CVSS 3.1
AVLACLPRLUINSCCNILAL
EPSS
0.36%
28.1th percentile
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.7+dfsg-1 (bookworm) | ansible 2.9.7+dfsg-1 (bookworm) |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 2.9.0a1 < 2.9.7 | 2.9.7 |
| redhat | ansible_engine | >= 2.9.0 < 2.9.7 | 2.9.7 |
| redhat | ansible_tower | — | — |
CVSS provenance
nvdv3.15.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Path Traversal in Ansible
ghsa·2021-04-20
CVE-2020-10691 [MEDIUM] CWE-22 Path Traversal in Ansible
Path Traversal in Ansible
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running `ansible-galaxy collection` install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
OSV
Path Traversal in Ansible
osv·2021-04-20
CVE-2020-10691 [MEDIUM] Path Traversal in Ansible
Path Traversal in Ansible
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running `ansible-galaxy collection` install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
OSV
CVE-2020-10691: An archive traversal flaw was found in all ansible-engine versions 2
osv·2020-04-30·CVSS 5.2
CVE-2020-10691 [MEDIUM] CVE-2020-10691: An archive traversal flaw was found in all ansible-engine versions 2
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Red Hat
Ansible: archive traversal vulnerability in ansible-galaxy collection install
vendor_redhat·2020-03-27·CVSS 5.2
CVE-2020-10691 [MEDIUM] CWE-22 Ansible: archive traversal vulnerability in ansible-galaxy collection install
Ansible: archive traversal vulnerability in ansible-galaxy collection install
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
An archive traversal flaw was found in Ansible Engine when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Statement: Ansible Engine 2.9.6 as well as previous 2.9.x versions are affected. Ansible versions less than or equal to 2.8 are no
Debian
CVE-2020-10691: ansible - An archive traversal flaw was found in all ansible-engine versions 2.9.x prior t...
vendor_debian·2020·CVSS 5.2
CVE-2020-10691 [MEDIUM] CVE-2020-10691: ansible - An archive traversal flaw was found in all ansible-engine versions 2.9.x prior t...
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Scope: local
bookworm: resolved (fixed in 2.9.7+dfsg-1)
bullseye: resolved (fixed in 2.9.7+dfsg-1)
forky: resolved (fixed in 2.9.7+dfsg-1)
sid: resolved (fixed in 2.9.7+dfsg-1)
trixie: resolved (fixed in 2.9.7+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [openstack-rdo]
bugzilla·2020-03-30·CVSS 5.2
CVE-2020-10691 [MEDIUM] CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [openstack-rdo]
CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fix l
Bugzilla
CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [epel-all]
bugzilla·2020-03-27·CVSS 5.2
CVE-2020-10691 [MEDIUM] CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [epel-all]
CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [fedora-all]
bugzilla·2020-03-27·CVSS 5.2
CVE-2020-10691 [MEDIUM] CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [fedora-all]
CVE-2020-10691 ansible: archive traversal vulnerability in ansible-galaxy collection install [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2020-10691 Ansible: archive traversal vulnerability in ansible-galaxy collection install
bugzilla·2020-03-25·CVSS 5.2
CVE-2020-10691 [MEDIUM] CVE-2020-10691 Ansible: archive traversal vulnerability in ansible-galaxy collection install
CVE-2020-10691 Ansible: archive traversal vulnerability in ansible-galaxy collection install
ansible-galaxy collection install has a archive traversal vulnerability when extracing a collection .tar.gz file, neither install() nor the called _extract_tar_file() does any sanitizing on the filename. This should allow a specially crafted collection .tar.gz file to place a file wherever it wants in the file system.
Discussion:
Mitigation:
A possible mitigation of archive traversal issue could be done by restricting file access control and directory write accesses for extracting tarball files. This is feasible only for scenarios when the destination path could be known and enforced beforehand.
---
Acknowledgments:
Name: Felix Fountein
---
Created ansible tracking bugs for this issue:
Af
2020-04-30
Published