CVE-2015-1368: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) orderby parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) nextrun parameter to api/v1/schedules/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1368?
CVE-2015-1368 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-1368?
To fix CVE-2015-1368, upgrade Ansible Tower to version 2.0.5 or later.
What systems are affected by CVE-2015-1368?
CVE-2015-1368 affects all versions of Ansible Tower prior to 2.0.5.
What types of attacks are possible with CVE-2015-1368?
CVE-2015-1368 allows remote attackers to execute arbitrary web scripts or HTML through cross-site scripting.
Is there a workaround for CVE-2015-1368?
There are no official workarounds for CVE-2015-1368; updating the software is recommended.