Red Hat, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with Ansible Tower.
Products
Clear product- keycloak6 vulnerabilities
- 389-ds-base3 vulnerabilities
- ceph3 vulnerabilities
- Gluster Storage for RHEL 63 vulnerabilities
- postgresql3 vulnerabilities
- resteasy3 vulnerabilities
- Ansible Tower2 vulnerabilities
- etcd2 vulnerabilities
- GlusterFS2 vulnerabilities
- Moodle2 vulnerabilities
- Wildfly2 vulnerabilities
- ansible1 vulnerability
- atomic-openshift1 vulnerability
- augeas1 vulnerability
- Cairo1 vulnerability
- CloudForms1 vulnerability
- curl1 vulnerability
- cygwin1 vulnerability
- dnsdist1 vulnerability
- DPDK1 vulnerability
- EAP-51 vulnerability
- fedora-arm-installer1 vulnerability
- hawtio1 vulnerability
- hibernate-validator1 vulnerability
- HornetQ/Artemis1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-1104HIGH | Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server. | CVSS8.8v3.0 | EPSS2.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-1101HIGH | Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system. | CVSS7.2v3.0 | EPSS2.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |