CVE-2020-1737
published 2020-03-09CVE-2020-1737: A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.5th percentile
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | < ansible 2.9.7+dfsg-1 (bookworm) | ansible 2.9.7+dfsg-1 (bookworm) |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| red_hat | ansible | — | — |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.9.7+dfsg-1 | 2.9.7+dfsg-1 |
| redhat | ansible | >= 0 < 2.7.17 | 2.7.17 |
| redhat | ansible | >= 2.8.0a1 < 2.8.9 | 2.8.9 |
| redhat | ansible | >= 2.9.0a1 < 2.9.6 | 2.9.6 |
| redhat | ansible_engine | < 2.7.17 | 2.7.17 |
| redhat | ansible_engine | >= 2.8.0 < 2.8.9 | 2.8.9 |
| redhat | ansible_engine | >= 2.9.0 < 2.9.6 | 2.9.6 |
| redhat | ansible_tower | <= 3.3.4 | — |
| redhat | ansible_tower | 3.4.0 – 3.4.5 | — |
| redhat | ansible_tower | 3.5.0 – 3.5.5 | — |
| redhat | ansible_tower | 3.6.0 – 3.6.3 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Path Traversal in Ansible
ghsa·2021-04-20
CVE-2020-1737 [HIGH] CWE-22 Path Traversal in Ansible
Path Traversal in Ansible
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
OSV
Path Traversal in Ansible
osv·2021-04-20
CVE-2020-1737 [HIGH] Path Traversal in Ansible
Path Traversal in Ansible
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
OSV
CVE-2020-1737: A flaw was found in Ansible 2
osv·2020-03-09·CVSS 7.8
CVE-2020-1737 [HIGH] CVE-2020-1737: A flaw was found in Ansible 2
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
Red Hat
ansible: Extract-Zip function in win_unzip module does not check extracted path
vendor_redhat·2020-02-18·CVSS 7.5
CVE-2020-1737 [HIGH] CWE-22 ansible: Extract-Zip function in win_unzip module does not check extracted path
ansible: Extract-Zip function in win_unzip module does not check extracted path
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
A flaw was found in the Ansible Engine when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal.
Statement: Ansible Engine 2.7.16
Debian
CVE-2020-1737: ansible - A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and pri...
vendor_debian·2020·CVSS 7.5
CVE-2020-1737 [HIGH] CVE-2020-1737: ansible - A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and pri...
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
Scope: local
bookworm: resolved (fixed in 2.9.7+dfsg-1)
bullseye: resolved (fixed in 2.9.7+dfsg-1)
forky: resolved (fixed in 2.9.7+dfsg-1)
sid: resolved (fixed in 2.9.7+dfsg-1)
trixie: resolved (fixed in 2.9.7+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [openstack-rdo]
bugzilla·2020-02-27·CVSS 7.5
CVE-2020-1737 [HIGH] CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [openstack-rdo]
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fixe
Bugzilla
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [epel-all]
bugzilla·2020-02-20·CVSS 7.5
CVE-2020-1737 [HIGH] CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [epel-all]
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [fedora-all]
bugzilla·2020-02-20·CVSS 7.5
CVE-2020-1737 [HIGH] CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [fedora-all]
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path
bugzilla·2020-02-12·CVSS 7.5
CVE-2020-1737 [HIGH] CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path
CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path
Extract-Zip function in win_unzip module does not check if the extracted path belongs to the destination folder. This could lead to path traversal on a crafted archive.
Discussion:
Acknowledgments:
Name: Damien Aumaitre (Quarkslab), Nicolas Surbayrole (Quarkslab)
---
Borja, any information on related upstream issue on this one? If possible it would be nice to have this together with the respective bugzilla entry to ease other downstream's triage on the issues.
---
Created ansible tracking bugs for this issue:
Affects: epel-all [bug 1805329]
Affects: fedora-all [bug 1805328]
---
Hey Salvatore, I am working to provide additional information regarding this issue; more details as you reques
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1737https://github.com/ansible/ansible/issues/67795https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FWDK3QUVBULS3Q3PQTGEKUQYPSNOU5M3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QT27K5ZRGDPCH7GT3DRI3LO4IVDVQUB7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3IMV3XEIUXL6S4KPLYYM4TVJQ2VNEP2/https://security.gentoo.org/glsa/202006-11https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1737https://github.com/ansible/ansible/issues/67795https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FWDK3QUVBULS3Q3PQTGEKUQYPSNOU5M3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QT27K5ZRGDPCH7GT3DRI3LO4IVDVQUB7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3IMV3XEIUXL6S4KPLYYM4TVJQ2VNEP2/https://security.gentoo.org/glsa/202006-11
2020-03-09
Published