First published: Wed Aug 22 2018(Updated: )
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Tower | >=3.1.0<=3.1.8 | |
Redhat Ansible Tower | >=3.2.0<=3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Ansible Tower vulnerability is CVE-2018-10884.
The severity of CVE-2018-10884 is high with a severity value of 8.8.
CVE-2018-10884 allows for cross-site request forgery (CSRF) attacks in Ansible Tower versions before 3.1.8 and 3.2.6.
An attacker can exploit CVE-2018-10884 by tricking authenticated users into visiting a malicious site and hijacking the authtoken cookie.
Yes, the fix for CVE-2018-10884 is to upgrade to Ansible Tower version 3.1.8 or 3.2.6.