#VU27558 Path traversal in Red Hat Ansible Engine - CVE-2020-10691
Published: May 6, 2020 / Updated: July 7, 2020
Red Hat Ansible Engine
Red Hat Inc.
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists when extracting a collection .tar.gz file, the directory is created without sanitizing the filename when running ansible-galaxy collection install. A remote user can send a specially crafted HTTP request and overwrite any file within the system.
This vulnerability affects versions 2.9.x prior to 2.9.7.