CVE Database
/

CVE-2020-1737

Back to search

CVE-2020-1737

Published: Mar 9, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.

VendorProductVersions

Red Hat

Ansible

affected
2.7.17 and prior
affected
2.8.9 and prior
affected
2.9.6 and prior
affected
fixed in 2.10

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

High

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

References

FEDORA-2020-a3f12bcff4
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-0cab7041f7
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-87f5e1e829
vendor-advisory
x_refsource_FEDORA
GLSA-202006-11
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now