ALPINE-CVE-2019-3828 PUBLISHED CVSS 4.199999809265137 MEDIUM

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

Risk Scores

CVSS v3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Alpine:v3.14ansible-base1.9.2-r1, 1.9.2-r0, 1.8.4-r0
Alpine:v3.10ansible0, 0.3.1-r0, 0.4-r0
Alpine:v3.11ansible1.6.6-r0, 0, 0.4-r0
Alpine:v3.13ansible-base1.9.4-r0, 2.7.0-r0, 1.9.2-r0
Alpine:v3.12ansible1.4.3-r0, 2.0.0.2-r1, 1.8.0-r0
Alpine:v3.9ansible1.2.1-r1, 1.2-r1, 1.1-r0
Alpine:v3.8ansible2.1.2.0-r0, 2.5.0-r0, 2.4.2.0-r0

Timeline

References

Open in Interactive Console →