A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ansible(PyPI) | 2.7.0a1 | 2.7.18 | N/A |
| ansible(PyPI) | 2.8.0a1 | 2.8.12 | N/A |
| ansible(PyPI) | 2.9.0a1 | 2.9.8 | N/A |
CVSS Metrics