Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
CVE-2023-5115
6.3MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 18 December 2023
What is CVE-2023-5115?
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Affected Version(s)
Red Hat Ansible Automation Platform 2.3 for RHEL 8 0:2.14.11-1.el8ap
Red Hat Ansible Automation Platform 2.3 for RHEL 9 0:2.14.11-1.el9ap
Red Hat Ansible Automation Platform 2.4 for RHEL 8 0:2.15.5-1.el8ap