CVE-2018-1101
published 2018-05-02CVE-2018-1101: Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System…
PriorityP342high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
2.01%
78.6th percentile
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | ansible_tower | — | — |
| redhat | ansible_tower | < 3.2.4 | 3.2.4 |
| redhat | cloudforms | — | — |
| redhat | cloudforms | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
vendor_redhat·2018-04-27·CVSS 7.2
CVE-2018-1101 [HIGH] CWE-266 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Ansible Tower, before version 3.2.4, has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
GHSA
GHSA-hfwp-5v2g-2vvc: Ansible Tower before version 3
ghsa_unreviewed·2022-05-13
CVE-2018-1101 [HIGH] CWE-521 GHSA-hfwp-5v2g-2vvc: Ansible Tower before version 3
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000411 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
bugzilla·2018-10-15·CVSS 6.5
CVE-2018-1000411 [MEDIUM] CVE-2018-1000411 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
CVE-2018-1000411 jenkins-plugin-junit: CSRF due to URL not requiring POST requests
A URL used to allow setting the description of a test object in JUnit Plugin did not require POST requests, resulting in a cross-site request forgery vulnerability.
References:
https://jenkins.io/security/advisory/2018-09-25/
Discussion:
External References:
https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1101
https://github.com/jenkinsci/junit-plugin/commit/091ee0dc8dd6023713827ce1a5914fa9fa9b6043
---
Statement:
For Openshift, Jenkins is used within the infrastructure and deployment in OCP. The package is delivered within the technology but not used by default in production environments. It requires additional configuration in running environments which would be mainly use on testing appl
Bugzilla
CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
bugzilla·2018-04-04·CVSS 7.2
CVE-2018-1101 [HIGH] CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Discussion:
This is now public: https://www.ansible.com/security
---
This issue has been addressed in Ansible Tower release 3.1.6 and 3.2.4, for more information please see https://www.ansible.com/security
---
Acknowledgments:
Name: Graham Mainwaring (Red Hat)
---
This issue has been addressed in the following products:
CloudForms Management En
https://access.redhat.com/errata/RHSA-2018:1328https://access.redhat.com/errata/RHSA-2018:1972https://access.redhat.com/security/cve/cve-2018-1101https://bugzilla.redhat.com/show_bug.cgi?id=1563492https://www.ansible.com/securityhttps://access.redhat.com/errata/RHSA-2018:1328https://access.redhat.com/errata/RHSA-2018:1972https://access.redhat.com/security/cve/cve-2018-1101https://bugzilla.redhat.com/show_bug.cgi?id=1563492https://www.ansible.com/security
2018-05-02
Published