SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1101

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation.

HIGH 7.2EPSS 1.98%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

CVSS 3.0
7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.98% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-266, CWE-521
Affected
redhat/ansible tower · redhat/cloudforms
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.