VDB

ALPINE-CVE-2019-3828

ALPINE-CVE-2019-3828 PUBLISHED CVSS 4.199999809265137 MEDIUM

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

Risk Scores

CVSS 3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Alpine:v3.14ansible-base1.4.1-r0, 1.4.3-r0, 1.4.5-r0
Alpine:v3.10ansible1.1-r1, 2.5.0, 2.8.9-r0
Alpine:v3.11ansible2.3.1.0-r0, 2.5.0, 2.9.6-r0
Alpine:v3.13ansible-base2.8.2-r0, 0.4-r0, 0.5-r0
Alpine:v3.12ansible2.5.0, 2.9.6-r0, 2.9.5-r0
Alpine:v3.9ansible2.5.0, 2.7.0-r1, 2.7.13-r0
Alpine:v3.8ansible2.5.5-r0, 2.5.4-r0, 2.5.2-r0

Timeline

  • Mar 27, 2019 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›