USN-4072-1: Ansible vulnerabilities
24 July 2019
Several security issues were fixed in Ansible.
- ansible - Configuration management, deployment, and task execution system
It was discovered that Ansible failed to properly handle sensitive information.
A local attacker could use those vulnerabilities to extract them.
It was discovered that Ansible could load configuration files from the current
working directory containing crafted commands. An attacker could run arbitrary
code as result.
It was discovered that Ansible fetch module had a path traversal vulnerability.
A local attacker could copy and overwrite files outside of the specified
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.