ansible is vulnerable to directory traversal. A lack of validation in the fetch module allows copying and overwriting of files outside of the specified destination in the local ansible controller host using the ../
characters.
lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html
lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html
lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html
access.redhat.com/errata/RHSA-2019:3744
access.redhat.com/errata/RHSA-2019:3789
bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3828
github.com/ansible/ansible/pull/52133
usn.ubuntu.com/4072-1/