Path traversal in Ansible - CVE-2019-3828

 

Path traversal in Ansible - CVE-2019-3828

Published: October 14, 2019


Vulnerability identifier: #VU21766
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3828
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and copy and overwrite files outside of the specified destination in the local ansible controller host.


Affected software

Ansible
Red Hat Ansible Engine
Red Hat OpenStack Director Deployment Tools
ansible (Alpine package)
ansible
ansible-help
Fedora
Opensuse
SUSE Linux
openEuler
SUSE Package Hub for SUSE Linux Enterprise
Red Hat OpenStack
Red Hat OpenStack for IBM Power

How to mitigate CVE-2019-3828

Install updates from vendor's website.

Ansible - addressed in versions 2.5.15, 2.6.14, 2.7.8, 2.5.15-1.el7ae, 2.6.14-1.el7ae, 2.6.19-1.el7ae, 2.7.8-1.el7ae
ansible (Alpine package) - update to 2.5.15-r0
ansible - update to 2.5.5-6
ansible-help - update to 2.5.5-6
ansible - addressed in versions 2.7.8-1.el7, 2.7.8-1.fc28, 2.7.8-1.fc29

External References

Related Security Bulletins