CVE-2017-12148
Summary
| CVE | CVE-2017-12148 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 16:29:00 UTC |
| Updated | 2019-10-09 23:22:00 UTC |
| Description | A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by Tower, modifies the checked out SCM repository to add git hooks. These git hooks could, in turn, cause arbitrary command and code execution as the user Tower runs as. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Ansible Tower | All | All | All | All |
| Application | Redhat | Ansible Tower | All | All | All | All |
| Application | Redhat | Ansible Tower | All | All | All | All |
| Application | Redhat | Ansible Tower | All | All | All | All |
| Application | Redhat | Cloudforms | 4.5 | All | All | All |
| Application | Redhat | Cloudforms | 4.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1485474 – (CVE-2017-12148) CVE-2017-12148 Ansible Tower:modification of git hooks in SCM repo via upstream playbook execution | CONFIRM | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.