Bug 1563492 (CVE-2018-1101) - CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges
Summary: CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organizatio...
Status: CLOSED ERRATA
Alias: CVE-2018-1101
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=important,public=20180427,repo...
Keywords: Security
Depends On: 1572745 1572746
Blocks: 1563493
TreeView+ depends on / blocked
 
Reported: 2018-04-04 02:34 UTC by Sam Fowler
Modified: 2019-06-11 11:13 UTC (History)
16 users (show)

(edit)
Ansible Tower, before version 3.2.4, has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Clone Of:
(edit)
Last Closed: 2019-06-10 10:19:33 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:1328 None None None 2018-05-07 20:42 UTC
Red Hat Product Errata RHSA-2018:1972 None None None 2018-06-25 14:17 UTC

Description Sam Fowler 2018-04-04 02:34:16 UTC
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Comment 2 Kurt Seifried 2018-05-02 16:04:43 UTC
This is now public: https://www.ansible.com/security

Comment 3 Kurt Seifried 2018-05-02 16:06:04 UTC
This issue has been addressed in Ansible Tower release 3.1.6 and 3.2.4, for more information please see https://www.ansible.com/security

Comment 5 Borja Tarraso 2018-05-03 06:21:45 UTC
Acknowledgments:

Name: Graham Mainwaring (Red Hat)

Comment 6 errata-xmlrpc 2018-05-07 20:42:22 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.9

Via RHSA-2018:1328 https://access.redhat.com/errata/RHSA-2018:1328

Comment 7 errata-xmlrpc 2018-06-25 14:16:54 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.8

Via RHSA-2018:1972 https://access.redhat.com/errata/RHSA-2018:1972


Note You need to log in before you can comment on or make changes to this bug.