Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-7070

Опубликовано: 11 сент. 2018
Источник: nvd
CVSS3: 8
CVSS2: 5.2
EPSS Низкий

Описание

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия до 3.0.3 (исключая)

EPSS

Процентиль: 25%
0.00088
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-266
CWE-264

Связанные уязвимости

CVSS3: 8
redhat
больше 9 лет назад

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.

CVSS3: 8
github
больше 3 лет назад

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.

EPSS

Процентиль: 25%
0.00088
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-266
CWE-264