Lucene search

K
redhatcveRedhat.comRH:CVE-2020-10691
HistoryMar 27, 2020 - 8:13 a.m.

CVE-2020-10691

2020-03-2708:13:18
redhat.com
access.redhat.com
14

0.0004 Low

EPSS

Percentile

9.9%

An archive traversal flaw was found in Ansible Engine when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Mitigation

A possible mitigation of archive traversal issue could be done by restricting file access control and directory write accesses for extracting tarball files. This is feasible only for scenarios when the destination path could be known and enforced beforehand.