cbcvebase.
CVE-2018-1101
published 2018-05-02

CVE-2018-1101: Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System…

PriorityP342high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
2.01%
78.6th percentile
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Affected

4 ranges
VendorProductVersion rangeFixed in
red_hat_incansible_tower
redhatansible_tower< 3.2.43.2.4
redhatcloudforms
redhatcloudforms

CVSS provenance

nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.