First published: Wed Apr 11 2018(Updated: )
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible-tower | <3.1.6 | 3.1.6 |
redhat/ansible-tower | <3.2.4 | 3.2.4 |
Redhat Ansible Tower | <=3.2.3 | |
Redhat Cloudforms | =4.5 | |
Redhat Cloudforms | =4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1104.
The severity of CVE-2018-1104 is high.
The affected software for CVE-2018-1104 includes Ansible Tower versions up to 3.2.3 and RedHat Cloudforms versions 4.5 and 4.6.
Users with access to define variables for a job template can exploit CVE-2018-1104 to execute arbitrary code on the Ansible Tower server.
You can find more information about CVE-2018-1104 on the Ansible website (https://www.ansible.com/security) and the RedHat website (https://access.redhat.com/errata/RHSA-2018:1328, https://access.redhat.com/errata/RHSA-2018:1972).