CVE-2015-1482
Ansible Tower < 2.0.4 - Unauthenticated Sensitive Information Exposure via WebSocket Connection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-1482. PoCs published by SEC Consult.
AI-analyzed exploit summary The advisory details multiple vulnerabilities in Ansible Tower <=2.0.2, including privilege escalation via the 'is_superuser' parameter, reflected XSS in API endpoints, and unauthenticated WebSocket connections leading to information leakage. Proof-of-concept requests and steps are provided for each vulnerability.
Description
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.
Exploits (1)
The advisory details multiple vulnerabilities in Ansible Tower <=2.0.2, including privilege escalation via the 'is_superuser' parameter, reflected XSS in API endpoints, and unauthenticated WebSocket connections leading to information leakage. Proof-of-concept requests and steps are provided for each vulnerability.