CVE Published: 18/12/2023 |
CVE Updated: 23/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Ansible Automation Platform 2.3 for RHEL 8 Status : PUBLISHED
CVE-2023-5115 Description
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.