Red Hat Bugzilla – Bug 1597069
CVE-2018-10884 ansible-tower: CSRF in awx/api/authentication.py allows for hijacking of the authtoken cookie
Last modified: 2018-08-23 17:13:53 EDT
Ansible Tower versions before 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.
Acknowledgments: Name: Chris Meyers (Red Hat)