First published: Wed Apr 04 2018(Updated: )
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Tower | <3.2.4 | |
Redhat Cloudforms | =4.5 | |
Redhat Cloudforms | =4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1101 is a vulnerability in Ansible Tower before version 3.2.4 that allows for privilege escalation.
CVE-2018-1101 has a severity rating of 7 (high).
To fix CVE-2018-1101, upgrade Ansible Tower to version 3.2.4 or above.
Ansible Tower versions up to and excluding 3.2.4 are affected by CVE-2018-1101.
Yes, you can find references for CVE-2018-1101 at the following links: [https://www.ansible.com/security](https://www.ansible.com/security), [https://access.redhat.com/errata/RHSA-2018:1328](https://access.redhat.com/errata/RHSA-2018:1328), [https://access.redhat.com/errata/RHSA-2018:1972](https://access.redhat.com/errata/RHSA-2018:1972).