|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2023-5115: ansible1,ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | Cathy Hu <cathy.hu> |
| Component: | Security | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED INVALID | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | cloud-bugs, robert.simai, security-team, stoyan.manolov |
| Version: | Leap 15.5 | ||
| Target Milestone: | Leap 15.5 | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/379607/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2023-5115:6.3:(AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Cathy Hu
2023-09-22 09:04:38 UTC
Patch: https://github.com/ansible/ansible/commit/ddf0311c63287e2d5334770377350c1e0cbfff28 Affected: - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update/ansible 2.9.27 - SUSE:SLE-15:Update/ansible 2.9.27 - SUSE:SLE-15:Update:Products:ManagerToolsBeta:Update/ansible 2.9.21 - openSUSE:Backports:SLE-15-SP4/ansible 2.9.27 - openSUSE:Factory/ansible-core 2.15.4 Not affected: - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update/ansible1 1.9.6 - SUSE:SLE-12-SP4:Update:Products:Cloud9:Update/ansible1 1.9.6 this does not need a submission, since unsupported: - SUSE:SLE-15:Update:Products:ManagerToolsBeta:Update/ansible 2.9.21 |