NA

CVE-2021-4112

Published: 25/08/2022 Updated: 12/02/2023
CVSS v3 Base Score: 8.8 | Impact Score: 6 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an malicious user to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible tower 3.0

redhat ansible automation platform early access 2.0

redhat ansible automation platform text-only advisories -

redhat ansible_automation_platform 2.0

redhat ansible_automation_platform 2.1

Vendor Advisories

Synopsis Important: Red Hat Ansible Automation Platform 21 ansible-runner security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for ansible-runner for Red Hat Ansible Automation Platf ...
Synopsis Important: Red Hat Ansible Ansible Tower 38 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Ansible Tower 38Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed ...
Synopsis Important: Red Hat Ansible Automation Platform 20 ansible-runner security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for ansible-runner for Red Hat Ansible Automation Platf ...
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment ...