Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1101

Опубликовано: 27 апр. 2018
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Ansible Tower, before version 3.2.4, has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1563492ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges

EPSS

Процентиль: 62%
0.00432
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
почти 8 лет назад

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

CVSS3: 7.2
github
больше 3 лет назад

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

EPSS

Процентиль: 62%
0.00432
Низкий

8 High

CVSS3