PYSEC-2019-75

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/ansible/PYSEC-2019-75.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2019-75
Withdrawn
2023-03-14T07:01:09.383328Z
Published
2019-03-27T13:29:00Z
Modified
2023-03-14T07:01:09.383328Z
Summary
[none]
Details

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

References

Affected packages

PyPI / ansible

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.0
Fixed
2.5.15
Introduced
2.6.0
Fixed
2.6.14
Introduced
2.7.0
Fixed
2.7.8

Affected versions

2.*
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.10
2.6.11
2.6.12
2.6.13
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/ansible/PYSEC-2019-75.yaml"