VDB
ALPINE-CVE-2019-3828
ALPINE-CVE-2019-3828
PUBLISHED
CVSS 4.199999809265137 MEDIUM
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
Risk Scores
CVSS 3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.14 | ansible-base | 1.4.1-r0, 1.4.3-r0, 1.4.5-r0 |
| Alpine:v3.10 | ansible | 1.1-r1, 2.5.0, 2.8.9-r0 |
| Alpine:v3.11 | ansible | 2.3.1.0-r0, 2.5.0, 2.9.6-r0 |
| Alpine:v3.13 | ansible-base | 2.8.2-r0, 0.4-r0, 0.5-r0 |
| Alpine:v3.12 | ansible | 2.5.0, 2.9.6-r0, 2.9.5-r0 |
| Alpine:v3.9 | ansible | 2.5.0, 2.7.0-r1, 2.7.13-r0 |
| Alpine:v3.8 | ansible | 2.5.5-r0, 2.5.4-r0, 2.5.2-r0 |
Timeline
- Mar 27, 2019 CVE Published
- Apr 30, 2026 Distribution Patch
- Jul 8, 2026 CVE Updated