CVE Vulnerabilities

CVE-2018-1101

Incorrect Privilege Assignment

Published: May 02, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Ansible_towerRedhat*3.2.4 (excluding)
CloudForms Management Engine 5.8RedHatansible-0:2.4.4.0-1.el7ae*
CloudForms Management Engine 5.8RedHatansible-tower-0:3.1.7-1.el7at*
CloudForms Management Engine 5.8RedHatcfme-0:5.8.4.5-1.el7cf*
CloudForms Management Engine 5.8RedHatcfme-appliance-0:5.8.4.5-1.el7cf*
CloudForms Management Engine 5.8RedHatcfme-gemset-0:5.8.4.5-1.el7cf*
CloudForms Management Engine 5.8RedHatpython-paramiko-0:2.1.1-4.el7*
CloudForms Management Engine 5.8RedHatrh-ruby23-rubygem-json-0:2.1.0-1.el7cf*
CloudForms Management Engine 5.9RedHatansible-0:2.4.4.0-1.el7ae*
CloudForms Management Engine 5.9RedHatansible-tower-0:3.2.4-1.el7at*
CloudForms Management Engine 5.9RedHatcfme-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatcfme-amazon-smartstate-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatcfme-appliance-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatcfme-gemset-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatdbus-api-service-0:1.0.1-3.el7cf*
CloudForms Management Engine 5.9RedHathttpd-configmap-generator-0:0.2.1-2.el7cf*
CloudForms Management Engine 5.9RedHatpostgresql96-0:9.6.6-1PGDG.el7*
CloudForms Management Engine 5.9RedHatpython-paramiko-0:2.1.1-4.el7*
CloudForms Management Engine 5.9RedHatrh-ruby23-rubygem-json-0:2.1.0-1.el7cf*
CloudForms Management Engine 5.9RedHatrh-ruby23-rubygem-qpid_proton-0:0.22.0-2.el7cf*

Potential Mitigations

References