CVE-2021-20253: Medium severity red hat ansible tower vulnerability
A flaw was found in ansible tower. Default installations are vulnerable to “Job Isolation” Escapes that allows an attacker to elevate to the “awx” user from outside the isolated environment.
Other sources
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in ansible-tower?
The vulnerability ID is CVE-2021-20253.
What is the severity level of CVE-2021-20253?
The severity level of CVE-2021-20253 is high.
What is the highest threat from CVE-2021-20253?
The highest threat from CVE-2021-20253 is to data confidentiality and integrity.
Which versions of ansible-tower are affected by CVE-2021-20253?
ansible-tower versions up to 3.8.2, 3.7.5, and 3.6.7 are affected by CVE-2021-20253.
How can I fix CVE-2021-20253?
To fix CVE-2021-20253, update ansible-tower to version 3.8.2, 3.7.5, or 3.6.7.