CVE-2020-1737

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
09/03/2020
Last modified:
07/11/2023

Description

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.7.17 (excluding)
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.9 (excluding)
cpe:2.3:a:redhat:ansible_engine:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.6 (excluding)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* 3.3.4 (including)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.5 (including)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.5 (including)
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.3 (including)