A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
2022-08-25T20:15:09.530
2024-11-21T06:36:55.670
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible_automation_platform_early_access | 2.0 | Yes |
Application | redhat | ansible_automation_platform_text-only_advisories | - | Yes |
Application | redhat | ansible_tower | 3.0 | Yes |
Application | redhat | ansible_automation_platform | 2.0 | Yes |
Application | redhat | ansible_automation_platform | 2.1 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | No |