6.8
CVSSv2

CVE-2018-10884

Published: 22/08/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ansible Tower prior to 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible tower

Vendor Advisories

Ansible Tower before versions 318 and 326 is vulnerable to cross-site request forgery (CSRF) in awx/api/authenticationpy An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie ...