CVE-2020-1737
Published: 9 March 2020
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
Priority
Status
Package | Release | Status |
---|---|---|
ansible Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
eoan |
Ignored
(end of life)
|
|
focal |
Needs triage
|
|
groovy |
Not vulnerable
(2.9.7+dfsg-1)
|
|
hirsute |
Not vulnerable
(2.9.7+dfsg-1)
|
|
impish |
Not vulnerable
(2.9.7+dfsg-1)
|
|
jammy |
Not vulnerable
(2.9.7+dfsg-1)
|
|
kinetic |
Not vulnerable
(2.9.7+dfsg-1)
|
|
lunar |
Not vulnerable
(2.9.7+dfsg-1)
|
|
mantic |
Not vulnerable
(2.9.7+dfsg-1)
|
|
trusty |
Needs triage
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |