USN-4072-1: Ansible vulnerabilities

24 July 2019

Several security issues were fixed in Ansible.



  • ansible - Configuration management, deployment, and task execution system


It was discovered that Ansible failed to properly handle sensitive information.
A local attacker could use those vulnerabilities to extract them.

It was discovered that Ansible could load configuration files from the current
working directory containing crafted commands. An attacker could run arbitrary
code as result.

It was discovered that Ansible fetch module had a path traversal vulnerability.
A local attacker could copy and overwrite files outside of the specified

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.