UNIX symbolic link following in Ansible - CVE-2023-5115

 

UNIX symbolic link following in Ansible - CVE-2023-5115

Published: October 4, 2023


Vulnerability identifier: #VU81467
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5115
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to files outside the application directory and overwrite them.


Affected software

Ansible
Amazon Linux AMI
openEuler
Fedora
Migration Toolkit for Containers
IBM Cloud Pak for Security
IBM Fusion HCI
Ansible Automation Platform
QRadar Suite
ansible-test
ansible-doc
ansible
ansible-core (Red Hat package)
ansible-core
python3x-django (Red Hat package)
python-django (Red Hat package)
automation-controller (Red Hat package)

How to mitigate CVE-2023-5115

Install updates from vendor's website.

Ansible - update to 2.16.0b2
Migration Toolkit for Containers - update to 1.8.2
QRadar Suite - update to 1.10.27.0
IBM Fusion HCI - update to 2.10.0
ansible-test - update to 2.9.27-7
ansible-doc - update to 2.9.27-7
ansible - update to 2.9.27-7
ansible-core (Red Hat package) - addressed in versions 2.14.11-1.el8ap, 2.14.11-1.el9ap, 2.15.5-1.el8ap, 2.15.5-1.el9ap
ansible-core - addressed in versions 2.14.11-1.fc37, 2.14.11-1.fc38, 2.16.0~b2-1.fc39
ansible-core - update to 2.15.3-1
python3x-django (Red Hat package) - update to 3.2.22-1.el8ap
python-django (Red Hat package) - update to 3.2.22-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.3.16-1.el8ap, 4.3.16-1.el9ap, 4.4.6-1.el8ap, 4.4.6-1.el9ap

External References

Related Security Bulletins