Showing 2 vulnerabilities on this page for Ansible Tower

Signals CISA KEV Ransomware Nuclei
Red Hat, Inc. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

CWE-20CWE-94May 2, 2018
CVSS8.8v3.0EPSS2.52%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

CWE-266CWE-521May 2, 2018
CVSS7.2v3.0EPSS2.01%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX