redhat ansible-tower CVE-2018-1101 vulnerability in Red Hat Products
Published on May 2, 2018

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Vendor Advisory Vendor Advisory NVD

Weakness Type

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2018-1101

stack.watch emails you whenever new vulnerabilities are published in Red Hat Ansible Tower or Red Hat Cloudforms. Just hit a watch button to start following.

 
 

Affected Versions

Red Hat, Inc. Ansible Tower Version before 3.2.4 is affected by CVE-2018-1101

Exploit Probability

EPSS
0.43%
Percentile
62.25%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.