ansible-jailexec@1.3.0

Ansible connection plugin for FreeBSD jails via jexec over SSH

  • latest version

    2.0.3

  • latest non vulnerable version

  • first published

    5 months ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ansible-jailexec package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Symlink Attack

    ansible-jailexec is an Ansible connection plugin for FreeBSD jails via jexec over SSH

    Affected versions of this package are vulnerable to Symlink Attack via the put_file process. An attacker can perform arbitrary root-owned file writes on the host system by placing a symbolic link inside the jail at or above the destination path before the file transfer occurs. This is only exploitable if the operator runs a copy/template/fetch-style task against the jail and the attacker has the ability to create a symlink in a directory that will be written to by an Ansible task.

    How to fix Symlink Attack?

    Upgrade ansible-jailexec to version 2.0.0 or higher.

    [,2.0.0)