PT-2023-5465 · Ansible+2 · Ansible+2
Mauro Matteo Cascella
·
Published
2023-09-21
·
Updated
2026-06-03
·
CVE-2023-5115
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:P/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible (affected versions not specified)
Description
An absolute path traversal attack exists in the Ansible automation platform, allowing an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path. The vulnerability is related to incorrect link resolution before accessing a file, which can allow an attacker to overwrite arbitrary files.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ansible
Astra Linux
Red Os