CVE-2023-5115 is an absolute path traversal vulnerability in the Ansible automation platform, affecting various Debian and Red Hat Ansible products. An attacker can exploit this flaw by crafting a malicious Ansible role, allowing them to overwrite files outside the intended extraction path via a symlink. With a CVSS score of 6.3 (Medium), this vulnerability requires user interaction (UI:R) and low privileges (PR:L) but can lead to high integrity impact (I:H). Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:* | ||
2.3CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_automation_platform:2.3:*:*:*:*:*:*:* | ||
2.4CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_inside:1.1:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-5115
Jun 11, 2024Ansible symlink attack vulnerability
Dec 28, 2023Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
Dec 12, 2023Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
Sep 21, 2023