CVE-2023-5189
Severity CVSS v4.0:
Pending analysis
Type:
CWE-23
Relative Path Traversal
Publication date:
14/11/2023
Last modified:
06/12/2024
Description
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://access.redhat.com/errata/RHSA-2023:7773
- https://access.redhat.com/errata/RHSA-2024:1536
- https://access.redhat.com/errata/RHSA-2024:2010
- https://access.redhat.com/security/cve/CVE-2023-5189
- https://bugzilla.redhat.com/show_bug.cgi?id=2234387
- https://access.redhat.com/errata/RHSA-2023:7773
- https://access.redhat.com/errata/RHSA-2024:1536
- https://access.redhat.com/errata/RHSA-2024:2010
- https://access.redhat.com/security/cve/CVE-2023-5189
- https://bugzilla.redhat.com/show_bug.cgi?id=2234387



