Ansible: path traversal in the fetch module
Published Mar 27, 2019
2.4
LOWCVSS 4.0
EPSS 0.53%
Description
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
Affected products
-
- Version 2.5.15StatusaffectedConstraints-
- Version 2.6.14StatusaffectedConstraints-
- Version 2.7.8StatusaffectedConstraints-
- Version
No data.
Red Hat Ansible Engine 2 for RHEL 7
ansible-0:2.7.8-1.el7ae
Fixed · RHSA-2019:0430
Red Hat Ansible Engine 2.5 for RHEL 7
ansible-0:2.5.15-1.el7ae
Fixed · RHSA-2019:0432
Red Hat Ansible Engine 2.6 for RHEL 7
ansible-0:2.6.14-1.el7ae
Fixed · RHSA-2019:0433
Red Hat Ansible Engine 2.7 for RHEL 7
ansible-0:2.7.8-1.el7ae
Fixed · RHSA-2019:0431
Red Hat OpenStack Platform 13.0 (Queens)
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:3789
Red Hat OpenStack Platform 14.0 (Rocky)
ansible-0:2.6.19-1.el7ae
Fixed · RHSA-2019:3744
CloudForms Management Engine 5
ansible
Out of support scope
Red Hat Ansible Tower 3
ansible
Affected
Red Hat Ceph Storage 2
ansible
Affected
Red Hat Ceph Storage 3
ansible
Affected
Red Hat OpenShift Container Platform 3.2
ansible
Will not fix
Red Hat OpenShift Container Platform 3.3
ansible
Will not fix
Red Hat OpenShift Container Platform 3.4
ansible
Will not fix
Red Hat OpenShift Container Platform 3.5
ansible
Will not fix
Red Hat OpenShift Container Platform 3.6
ansible
Will not fix
Red Hat OpenShift Container Platform 3.7
ansible
Will not fix
Red Hat OpenStack Platform 10 (Newton)
ansible
Will not fix
Red Hat Storage 3
ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Engine 2 for RHEL 7 | ansible-0:2.7.8-1.el7ae | Fixed | RHSA-2019:0430 |
| Red Hat Ansible Engine 2.5 for RHEL 7 | ansible-0:2.5.15-1.el7ae | Fixed | RHSA-2019:0432 |
| Red Hat Ansible Engine 2.6 for RHEL 7 | ansible-0:2.6.14-1.el7ae | Fixed | RHSA-2019:0433 |
| Red Hat Ansible Engine 2.7 for RHEL 7 | ansible-0:2.7.8-1.el7ae | Fixed | RHSA-2019:0431 |
| Red Hat OpenStack Platform 13.0 (Queens) | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:3789 |
| Red Hat OpenStack Platform 14.0 (Rocky) | ansible-0:2.6.19-1.el7ae | Fixed | RHSA-2019:3744 |
| CloudForms Management Engine 5 | ansible | Out of support scope | n/a |
| Red Hat Ansible Tower 3 | ansible | Affected | n/a |
| Red Hat Ceph Storage 2 | ansible | Affected | n/a |
| Red Hat Ceph Storage 3 | ansible | Affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.3 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.4 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | ansible | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | ansible | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | ansible | Will not fix | n/a |
| Red Hat Storage 3 | ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat CloudForms 4.5 and 4.6 are now in Maintenance Support Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat CloudForms Life Cycle: https://access.redhat.com/support/policy/updates/cloudforms/
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
AV:L/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.53% (0.00526) | 42.47th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.52% (0.00522) | 39.92th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.12% (0.00117) | 28.06th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00055) | 24.84th | v3 (v2023.03.01) |
| Jun 11, 2024 | 0.06% (0.00055) | 22.67th | v3 (v2023.03.01) |
| Mar 20, 2024 | 0.06% (0.00055) | 20.66th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00047) | 14.28th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.10% (0.01104) | 54.09th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.10% (0.01104) | 52.45th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.10% (0.01104) | 50.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.41% (0.04411) | 70.76th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.85% (0.07855) | 85.01th | v1 |
| Jan 6, 2022 | 7.85% (0.07855) | 84.84th | v1 |
| Sep 1, 2021 | 1.86% (0.01865) | 76.13th | v1 |
| Apr 14, 2021 | 1.86% (0.01865) | 0.00th | v1 |
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00021.html vendor-advisoryThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00077.html vendor-advisoryThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00020.html vendor-advisoryThird Party Advisory
- http://packetstormsecurity.com/files/172837/Ansible-Fetch-Path-Traversal.html
- https://access.redhat.com/errata/RHSA-2019:3744 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3789 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3828 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1676689 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3828 Issue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-74vq-h4q8-x6jv Advisory
- https://github.com/ansible/ansible/commit/396a2f74717477d80600450e2b7e45349d7b5110
- https://github.com/ansible/ansible/commit/4be3215d2f9f84ca283895879f0c6ce1ed7dd333
- https://github.com/ansible/ansible/commit/f3edc091523fbe301926b7a0db25fbbd96940d93
- https://github.com/ansible/ansible/pull/52133 PatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2019-5.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-3828
- https://usn.ubuntu.com/4072-1 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3828
Change history (0)
No recorded changes yet.