Security Advisory

CVE-2019-3828

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-03-27 00:00:00
Last updated 2024-08-04 19:19:18
Assigner redhat
CVSS score 4.2
State PUBLISHED

Description

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.