An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Published: 2020-04-30
Updated: 2024-11-21
Base Score: 3.6
Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:P
Severity: Low
Base Score: 5.2
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Severity: Medium
Base Score: 4.8
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Severity: Medium