CVE-2021-4112: High severity red hat ansible automation platform vulnerability
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
Other sources
A researcher found a trivial bypass for CVE-2021-20253 by sending a mail to awx user, thereby leveraging postfix to create a folder, owned by awx, then placing a binary in that folder that lets a low privilege user to elevate to awx outside the isolation jail.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-4112.
What is the severity of CVE-2021-4112?
The severity of CVE-2021-4112 is high.
How does CVE-2021-4112 impact Ansible Tower?
CVE-2021-4112 impacts Ansible Tower by allowing an attacker to elevate privileges from a low privileged user to an AWX user outside the isolated environment.
Which software versions are affected by CVE-2021-4112?
The affected software versions include Redhat Ansible Automation Platform Early Access 2.0, Redhat Ansible Automation Platform Text-only Advisories, Redhat Ansible Tower 3.0, Redhat Ansible Automation Platform 2.0, and Redhat Ansible Automation Platform 2.1.
How can I mitigate the vulnerability CVE-2021-4112?
To mitigate CVE-2021-4112, update to the patched versions mentioned in the Red Hat Security Advisories RHSA-2022:0460 and RHSA-2022:0474.