CVE-2021-20253
09.03.2021, 18:15
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ansible_tower | 𝑥 < 3.6.7 |
redhat | ansible_tower | 3.7.0 ≤ 𝑥 < 3.7.5 |
redhat | ansible_tower | 3.8.0 ≤ 𝑥 < 3.8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration