Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20253

Опубликовано: 08 мар. 2021
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerAffected
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHSA-2021:077809.03.2021
Red Hat Ansible Tower 3.7 for RHEL 7ansible-tower-37/ansible-tower-rhel7FixedRHSA-2021:077909.03.2021
Red Hat Ansible Tower 3.8 for RHEL 7ansible-tower-38/ansible-runner-rhel7FixedRHSA-2021:078009.03.2021
Red Hat Ansible Tower 3.8 for RHEL 7ansible-tower-38/ansible-tower-rhel7FixedRHSA-2021:078009.03.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=1928847ansible-tower: Privilege escalation via job isolation escape

EPSS

Процентиль: 51%
0.00278
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
почти 5 лет назад

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

github
больше 3 лет назад

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

Процентиль: 51%
0.00278
Низкий

6.7 Medium

CVSS3