First published: Tue Mar 09 2021(Updated: )
Security Fix(es):<br><li> Addressed a security issue which can allow a malicious playbook author to elevate to the awx user from outside the isolated environment: CVE-2021-20253</li> <li> Upgraded to a more recent version of nginx to address CVE-2019-20372</li> <li> Upgraded to a more recent version of autobahn to address CVE-2020-35678</li> <li> Upgraded to a more recent version of jquery to address CVE-2020-11022 and CVE-2020-11023</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Ansible Tower |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:0778 is primarily focused on addressing vulnerabilities that could allow unauthorized privilege escalation to the awx user.
To fix RHSA-2021:0778, you should apply the recommended updates available for the affected software.
RHSA-2021:0778 addresses a privilege escalation issue associated with CVE-2021-20253 and upgrades to resolve CVE-2019-20372.
Users and administrators of the affected Red Hat software who have configured isolated environments are at risk with RHSA-2021:0778.
It is advised to update the affected software as outlined in RHSA-2021:0778 to mitigate the vulnerabilities before continuing safe usage.