Bugzilla – Bug 1215606
VUL-0: CVE-2023-5115: ansible1,ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
Last modified: 2024-02-26 04:53:32 UTC
CVE-2023-5115 When installing a maliciously created Ansible role using `ansible-galaxy role install`, arbitrary files the user has access to can be overwritten. The malicious role must contain a symlink with an absolute path to the target file, followed by a file of the same name (as the symlink) with the contents to write to the target. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-5115 https://bugzilla.redhat.com/show_bug.cgi?id=2233810
Patch: https://github.com/ansible/ansible/commit/ddf0311c63287e2d5334770377350c1e0cbfff28 Affected: - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update/ansible 2.9.27 - SUSE:SLE-15:Update/ansible 2.9.27 - SUSE:SLE-15:Update:Products:ManagerToolsBeta:Update/ansible 2.9.21 - openSUSE:Backports:SLE-15-SP4/ansible 2.9.27 - openSUSE:Factory/ansible-core 2.15.4 Not affected: - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update/ansible1 1.9.6 - SUSE:SLE-12-SP4:Update:Products:Cloud9:Update/ansible1 1.9.6
this does not need a submission, since unsupported: - SUSE:SLE-15:Update:Products:ManagerToolsBeta:Update/ansible 2.9.21