Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfwp-5v2g-2vvc

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

EPSS

Процентиль: 62%
0.00432
Низкий

7.2 High

CVSS3

Дефекты

CWE-521

Связанные уязвимости

CVSS3: 8
redhat
почти 8 лет назад

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

CVSS3: 7.2
nvd
почти 8 лет назад

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

EPSS

Процентиль: 62%
0.00432
Низкий

7.2 High

CVSS3

Дефекты

CWE-521