cbcvebase.
CVE-2021-20253
published 2021-03-09

CVE-2021-20253: A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low…

PriorityP428medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.41%
33.6th percentile
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

3 ranges
VendorProductVersion rangeFixed in
redhatansible_tower< 3.6.73.6.7
redhatansible_tower>= 3.7.0 < 3.7.53.7.5
redhatansible_tower>= 3.8.0 < 3.8.23.8.2

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.03.5LOWAV:L/AC:H/Au:S/C:P/I:P/A:P
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.