CVE-2021-20253

MEDIUM

Ansible-Tower - Privilege Escalation

Title source: llm
STIX 2.1

Description

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Exploits (1)

nomisec SUSPICIOUS 1 stars
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2021-20253

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1928847

Scores

CVSS v3 6.7
EPSS 0.0028
EPSS Percentile 51.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-552
Status published
Products (1)
redhat/ansible_tower < 3.6.7
Published Mar 09, 2021
Tracked Since Feb 18, 2026