Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.
2018-08-22T14:29:00.240
2024-11-21T03:42:13.377
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | ansible_tower | ≤ 3.1.8 | Yes |
| Application | redhat | ansible_tower | ≤ 3.2.6 | Yes |