Safety vulnerability ID: 63065
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Galaxy-importer 0.4.18 includes a fix for CVE-2023-5189: A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.
https://bugzilla.redhat.com/show_bug.cgi?id=2234387
https://github.com/ansible/galaxy-importer/commit/5e19ba6052dca04cd1759bd3da53ef164dcc19cc
Latest version: 0.5.0
Galaxy content importer
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application