CVE-2018-1104: Code Injection
Published Apr 11, 2018
·Updated
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
Affected Software
5 affected componentsFixes available
redhat/ansible-tower<3.1.6
3.1.6
redhat/ansible-tower<3.2.4
3.2.4
redhat Ansible Tower<=3.2.3
redhat Cloudforms=4.5
redhat Cloudforms=4.6
Event History
May 2, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Ansible Tower vulnerability?
The vulnerability ID is CVE-2018-1104.
2
What is the severity of CVE-2018-1104?
The severity of CVE-2018-1104 is high.
3
What is the affected software for CVE-2018-1104?
The affected software for CVE-2018-1104 includes Ansible Tower versions up to 3.2.3 and RedHat Cloudforms versions 4.5 and 4.6.
4
How can users exploit CVE-2018-1104?
Users with access to define variables for a job template can exploit CVE-2018-1104 to execute arbitrary code on the Ansible Tower server.
5
Where can I find more information about CVE-2018-1104?
You can find more information about CVE-2018-1104 on the Ansible website (https://www.ansible.com/security) and the RedHat website (https://access.redhat.com/errata/RHSA-2018:1328, https://access.redhat.com/errata/RHSA-2018:1972).