NA

CVE-2023-5115

Published: 18/12/2023 Updated: 29/12/2023
CVSS v3 Base Score: 6.3 | Impact Score: 4.2 | Exploitability Score: 2.1
VMScore: 0

Vulnerability Summary

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an malicious user to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible_automation_platform 1.2

redhat ansible_automation_platform 2.3

redhat ansible_automation_platform 2.4

redhat ansible_inside 1.1

redhat ansible_inside 1.2

redhat ansible_developer 1.0

redhat ansible_developer 1.1

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1053693 ansible-core: CVE-2023-5115 Package: src:ansible-core; Maintainer for src:ansible-core is Lee Garrett <debian@rocketjumpeu>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 8 Oct 2023 20:45:01 UTC Severity: important Tags: security, upstream Found in version ansib ...
概述 Moderate: Red Hat Ansible Automation Platform 23 Product Security and Bug Fix Update 类型/严重性 Security Advisory: Moderate Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 An update is now available for Red Hat Ansible Automation Platform 23Red Hat Product Se ...
Synopsis Moderate: Red Hat Ansible Automation Platform 24 Product Security and Bug Fix Update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 24Red Hat P ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 182 security and bug fix update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 182 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...