PT-2018-4976 · Red Hat · Ansible Tower
Andrej Nemec
·
Published
2018-09-11
·
Updated
2019-10-09
·
CVE-2016-7070
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ansible Tower versions prior to 3.0.3
Description
A privilege escalation flaw was found in Ansible Tower, where it incorrectly configures the trust level of the
postgres user when deploying a PostgreSQL database. This allows an attacker to gain admin level access to the database.Recommendations
For versions prior to 3.0.3, update to version 3.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the PostgreSQL database to minimize the risk of exploitation.
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ansible Tower