Path traversal in Ansible - CVE-2019-3828
Published: October 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and copy and overwrite files outside of the specified destination in the local ansible controller host.
Affected software
Red Hat Ansible Engine
Red Hat OpenStack Director Deployment Tools
ansible (Alpine package)
ansible
ansible-help
Fedora
Opensuse
SUSE Linux
openEuler
SUSE Package Hub for SUSE Linux Enterprise
Red Hat OpenStack
Red Hat OpenStack for IBM Power
How to mitigate CVE-2019-3828
ansible (Alpine package) - update to 2.5.15-r0
ansible - update to 2.5.5-6
ansible-help - update to 2.5.5-6
ansible - addressed in versions 2.7.8-1.el7, 2.7.8-1.fc28, 2.7.8-1.fc29
External References
Related Security Bulletins
- Path traversal in Red Hat Ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- OpenSUSE Linux update for ansible
- Path traversal in ansible (Alpine package)
- Ansible Engine 2 update for ansible
- Ansible Engine 2.7 update for ansible
- Ansible Engine 2.5 update for ansible
- Ansible Engine 2.6 update for ansible
- Red Hat OpenStack Platform 14 update for ansible
- Red Hat OpenStack Platform 13 update for ansible
- openEuler update for ansible
- Fedora 29 update for ansible
- Fedora 28 update for ansible
- Fedora EPEL 7 update for ansible