CVE-2020-1737: Red Hat Ansible Engine
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This issue is fixed in 2.10.
Affected products
- Red Hat Ansible Engine: before 2.7.17 (fixed in 2.7.17); from 2.8.0, before 2.8.9 (fixed in 2.8.9); from 2.9.0, before 2.9.6 (fixed in 2.9.6)
- Red Hat Ansible Tower: up to and including 3.3.4; from 3.4.0, up to and including 3.4.5; from 3.5.0, up to and including 3.5.5; from 3.6.0, up to and including 3.6.3
Published 2020-03-09. Last modified 2026-06-17.