PT-2020-12287 · Ansible+1 · Ansible Engine+1

Jborean93

·

Published

2020-04-30

·

Updated

2025-11-21

·

CVE-2020-10691

CVSS v3.1

5.2

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions ansible-engine versions 2.9.x prior to 2.9.7
Description An archive traversal flaw was found in ansible-engine when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
Recommendations For versions 2.9.x prior to 2.9.7, update to version 2.9.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of ansible-galaxy collection install until a patch is applied. Avoid extracting collection .tar.gz files from untrusted sources to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2341
ALT-PU-2020-3006
ALT-PU-2021-1800
CVE-2020-10691
GHSA-3C67-GC48-983W
OPENSUSE-SU-2022:0081-1
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
PYSEC-2020-2
RHSA-2020:1541
RHSA-2020:1542
SUSE-SU-2020:3309-1

Affected Products

Alt Linux
Ansible Engine