CVE-2016-7070: High severity red hat ansible tower vulnerability
Published Sep 11, 2018
·Updated
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.
Affected Software
1 affected component
redhat Ansible Tower<3.0.3
Event History
Sep 11, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this privilege escalation flaw in Ansible Tower?
The vulnerability ID is CVE-2016-7070.
2
What is the severity of CVE-2016-7070?
The severity of CVE-2016-7070 is high.
3
How does CVE-2016-7070 affect Ansible Tower?
CVE-2016-7070 allows an attacker to gain admin level access to the PostgreSQl database deployed by Ansible Tower.
4
What is the fix for CVE-2016-7070?
To fix CVE-2016-7070, update Ansible Tower to version 3.0.3 or later.
5
Where can I find more information about CVE-2016-7070?
More information about CVE-2016-7070 can be found at the following references: [1] [2]