Back

MEDIUM

ansible: path injection on dest parameter in fetch module

Published Mar 16, 2020

Description

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.

Affected products

Remediation

Red Hat statement

Ansible Engine 2.7.16, 2.8.10, and 2.9.6 as well as previous versions are affected. Ansible Tower 3.4.5, 3.5.5 and 3.6.3 as well as previous versions are affected. In Red Hat OpenStack Platform, because the flaw has a lower impact, ansible is not directly customer exposed, and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP ansible package.

Red Hat mitigation

Currently, there is no mitigation for this issue except avoid using the affected fetch module when possible.

Weaknesses (1)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 16, 2020
Updated Aug 4, 2024
Reserved Nov 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 18, 2020
GHSA-GFR2-QPXH-QJ9M