RHSA-2021:0779: Important: Red Hat Ansible Tower 3.7.5-1 - Container security and bug fix update
Security Fix(es): Addressed a security issue which can allow a malicious playbook author to elevate to the awx user from outside the isolated environment: CVE-2021-20253 Upgraded to a more recent version of autobahn to address CVE-2020-35678. Upgraded to a more recent version of nginx to address CVE-2019-20372. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Fixed a bug which can intermittently cause access to encrypted Tower settings to fail, resulting in failed job launches. Improved analytics collection to collect the playbook status for all hosts in a playbook run
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0779?
The severity of RHSA-2021:0779 is critical due to the potential for privilege escalation vulnerabilities.
How do I fix RHSA-2021:0779?
To fix RHSA-2021:0779, you should upgrade to the latest version of Red Hat Ansible Tower as specified in the security advisory.
What specific vulnerabilities are addressed in RHSA-2021:0779?
RHSA-2021:0779 addresses the privilege escalation issue linked to CVE-2021-20253 and also upgrades components to resolve CVE-2020-35678.
Which software is affected by RHSA-2021:0779?
RHSA-2021:0779 affects Red Hat Ansible Tower.
Is there a workaround for RHSA-2021:0779?
There is no official workaround for RHSA-2021:0779; the recommended action is to apply the appropriate security updates.