Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22915
HistoryApr 02, 2020 - 3:39 a.m.

Directory Traversal

2020-04-0203:39:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.0004 Low

EPSS

Percentile

9.9%

ansible is vulnerable to directory traversal. When extracting a collection of .tar.gz file, neither install() nor the called _extract_tar_file() performs any validation or sanitization of the filenames. This allows a malicious collection of .tar.gz file to be written in arbitrary location on the file system.