Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2568

Опубликовано: 15 авг. 2022
Источник: redhat
CVSS3: 7.2

Описание

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2automation hubNot affected
Red Hat Ansible Automation Platform 2.1 for RHEL 8python-galaxy-ngFixedRHSA-2022:607816.08.2022
Red Hat Ansible Automation Platform 2.2 for RHEL 8python3x-galaxy-ngFixedRHSA-2022:607916.08.2022
Red Hat Ansible Automation Platform 2.2 for RHEL 9python-galaxy-ngFixedRHSA-2022:607916.08.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2108653Ansible: Logic flaw leads to privilage escalation

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

CVSS3: 6.5
nvd
больше 3 лет назад

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

CVSS3: 6.5
github
больше 3 лет назад

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

7.2 High

CVSS3