Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-1481. PoCs published by SEC Consult.
AI-analyzed exploit summary The advisory details multiple vulnerabilities in Ansible Tower <=2.0.2, including privilege escalation via the 'is_superuser' parameter, reflected XSS in API endpoints, and unauthenticated WebSocket connections leading to information leakage. Proof-of-concept requests and steps are provided for each vulnerability.
Description
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
Exploits (1)
The advisory details multiple vulnerabilities in Ansible Tower <=2.0.2, including privilege escalation via the 'is_superuser' parameter, reflected XSS in API endpoints, and unauthenticated WebSocket connections leading to information leakage. Proof-of-concept requests and steps are provided for each vulnerability.