CVE-2018-1101
Summary
| CVE | CVE-2018-1101 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-02 18:29:00 UTC |
| Updated | 2019-10-09 23:38:00 UTC |
| Description | Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system. |
Risk And Classification
Problem Types: CWE-521
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Ansible Tower | All | All | All | All |
| Application | Redhat | Ansible Tower | All | All | All | All |
| Application | Redhat | Cloudforms | 4.5 | All | All | All |
| Application | Redhat | Cloudforms | 4.6 | All | All | All |
| Application | Redhat | Cloudforms | 4.5 | All | All | All |
| Application | Redhat | Cloudforms | 4.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Ansible Security Disclosures | CONFIRM | www.ansible.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| CVE-2018-1101 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| 1563492 – (CVE-2018-1101) CVE-2018-1101 ansible-tower: Privilege escalation flaw allows for organization admins to obtain system privileges | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.