{"id":"CVE-2020-1735","aliases":["GHSA-gfr2-qpxh-qj9m","PYSEC-2020-7"],"url":"https://o3.security/vulnerability/CVE-2020-1735","summary":"Path Traversal in Ansible","details":"A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.","published":"2020-03-16T16:15:13.890Z","modified":"2026-08-07T11:31:27.113169184Z","cvss":{"score":4.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.7.18"},{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.8.12"},{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.9.8"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQVOQD4VAIXXTVQAJKTN7NUGTJFE2PCB/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202006-11"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4950"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1735"},{"type":"FIX","url":"https://github.com/ansible/ansible/issues/67793"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:27.113169184Z"}}