First published: Tue Sep 11 2018(Updated: )
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Tower | <3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2016-7070.
The severity of CVE-2016-7070 is high.
CVE-2016-7070 allows an attacker to gain admin level access to the PostgreSQl database deployed by Ansible Tower.
To fix CVE-2016-7070, update Ansible Tower to version 3.0.3 or later.
More information about CVE-2016-7070 can be found at the following references: [1] [2]