CVE Vulnerabilities

CVE-2016-7070

Published: Sep 11, 2018 | Modified: Oct 09, 2019
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5.2 MEDIUM
AV:A/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 MODERATE
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.

Affected Software

Name Vendor Start Version End Version
Ansible_tower Redhat * 3.0.3 (excluding)

References