CVE Vulnerabilities

CVE-2018-1101

Incorrect Privilege Assignment

Published: May 02, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Ubuntu

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Ansible_tower Redhat * 3.2.4 (excluding)
CloudForms Management Engine 5.8 RedHat ansible-0:2.4.4.0-1.el7ae *
CloudForms Management Engine 5.8 RedHat ansible-tower-0:3.1.7-1.el7at *
CloudForms Management Engine 5.8 RedHat cfme-0:5.8.4.5-1.el7cf *
CloudForms Management Engine 5.8 RedHat cfme-appliance-0:5.8.4.5-1.el7cf *
CloudForms Management Engine 5.8 RedHat cfme-gemset-0:5.8.4.5-1.el7cf *
CloudForms Management Engine 5.8 RedHat python-paramiko-0:2.1.1-4.el7 *
CloudForms Management Engine 5.8 RedHat rh-ruby23-rubygem-json-0:2.1.0-1.el7cf *
CloudForms Management Engine 5.9 RedHat ansible-0:2.4.4.0-1.el7ae *
CloudForms Management Engine 5.9 RedHat ansible-tower-0:3.2.4-1.el7at *
CloudForms Management Engine 5.9 RedHat cfme-0:5.9.2.4-1.el7cf *
CloudForms Management Engine 5.9 RedHat cfme-amazon-smartstate-0:5.9.2.4-1.el7cf *
CloudForms Management Engine 5.9 RedHat cfme-appliance-0:5.9.2.4-1.el7cf *
CloudForms Management Engine 5.9 RedHat cfme-gemset-0:5.9.2.4-1.el7cf *
CloudForms Management Engine 5.9 RedHat dbus-api-service-0:1.0.1-3.el7cf *
CloudForms Management Engine 5.9 RedHat httpd-configmap-generator-0:0.2.1-2.el7cf *
CloudForms Management Engine 5.9 RedHat postgresql96-0:9.6.6-1PGDG.el7 *
CloudForms Management Engine 5.9 RedHat python-paramiko-0:2.1.1-4.el7 *
CloudForms Management Engine 5.9 RedHat rh-ruby23-rubygem-json-0:2.1.0-1.el7cf *
CloudForms Management Engine 5.9 RedHat rh-ruby23-rubygem-qpid_proton-0:0.22.0-2.el7cf *

Potential Mitigations

References