Back

MEDIUM

Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files

Published Dec 18, 2023

Description

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 18, 2023
Updated Nov 20, 2025
Reserved Sep 21, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 21, 2023
GHSA-JPVW-P8PR-9G2X