CVE-2018-1101: High severity red hat ansible tower vulnerability
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1101?
CVE-2018-1101 is a vulnerability in Ansible Tower before version 3.2.4 that allows for privilege escalation.
How severe is CVE-2018-1101?
CVE-2018-1101 has a severity rating of 7 (high).
How can I fix CVE-2018-1101?
To fix CVE-2018-1101, upgrade Ansible Tower to version 3.2.4 or above.
Which software versions are affected by CVE-2018-1101?
Ansible Tower versions up to and excluding 3.2.4 are affected by CVE-2018-1101.
Are there any references for CVE-2018-1101?
Yes, you can find references for CVE-2018-1101 at the following links: [https://www.ansible.com/security](https://www.ansible.com/security), [https://access.redhat.com/errata/RHSA-2018:1328](https://access.redhat.com/errata/RHSA-2018:1328), [https://access.redhat.com/errata/RHSA-2018:1972](https://access.redhat.com/errata/RHSA-2018:1972).