CVE-2021-4112

Related Vulnerabilities: CVE-2021-4112  

A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment.

Description

A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment.

Additional Information

  • Bugzilla 2028121: CVE-2021-4112 ansible-tower: Privilege escalation via job isolation escape
  • CWE-552: Files or Directories Accessible to External Parties
  • FAQ: Frequently asked questions about CVE-2021-4112