PT-2022-17458 · Ansible · Ansible Automation Platform

Vipul Nair

·

Published

2022-08-18

·

Updated

2023-02-12

·

CVE-2022-2568

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ansible Automation Platform (affected versions not specified)
Description A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with change user permissions to modify the account settings of the superuser account and also remove the superuser privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-2568
RHSA-2022:6078
RHSA-2022:6079

Affected Products

Ansible Automation Platform