CVE-2020-10691: Red Hat Ansible Engine

Medium severity, CVSS 5.2. EPSS: 0.3% chance of exploitation in the next 30 days.

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

Affected products

  • Red Hat Ansible Engine: from 2.9.0, before 2.9.7 (fixed in 2.9.7)
  • Red Hat Ansible Tower: version 3.0 only

Published 2020-04-30. Last modified 2026-06-17.