CVE-2018-10884: CSRF
Published Aug 22, 2018
·Updated
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.
Affected Software
2 affected components
redhat Ansible Tower>=3.1.0<=3.1.8
redhat Ansible Tower>=3.2.0<=3.2.6
Event History
Aug 22, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Ansible Tower vulnerability?
The vulnerability ID for this Ansible Tower vulnerability is CVE-2018-10884.
2
What is the severity of CVE-2018-10884?
The severity of CVE-2018-10884 is high with a severity value of 8.8.
3
How does CVE-2018-10884 impact Ansible Tower?
CVE-2018-10884 allows for cross-site request forgery (CSRF) attacks in Ansible Tower versions before 3.1.8 and 3.2.6.
4
How can an attacker exploit CVE-2018-10884?
An attacker can exploit CVE-2018-10884 by tricking authenticated users into visiting a malicious site and hijacking the authtoken cookie.
5
Is there a fix for CVE-2018-10884?
Yes, the fix for CVE-2018-10884 is to upgrade to Ansible Tower version 3.1.8 or 3.2.6.