CVE-2018-1101
Last modified
CVE-2018-1101 is a vulnerability of currently unknown severity. Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Tower | < 3.2.4 |
| Redhat | Cloudforms | 4.5 |
| Redhat | Cloudforms | 4.6 |
References
- https://access.redhat.com/errata/RHSA-2018:1328Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1972Third Party Advisory
- https://access.redhat.com/security/cve/cve-2018-1101Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1563492Issue Tracking, Third Party Advisory
- https://www.ansible.com/securityVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1328Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1972Third Party Advisory
- https://access.redhat.com/security/cve/cve-2018-1101Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1563492Issue Tracking, Third Party Advisory
- https://www.ansible.com/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1101?
How severe is CVE-2018-1101?
How do I fix CVE-2018-1101?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11004An issue was discovered in SDcms v1.5. Cross-site request fo…
- CVE-2018-11005A Memory Leak issue was discovered in K7Computing K7AntiViru…5.5
- CVE-2018-11006An Incorrect Access Control issue was discovered in K7Comput…5.5
- CVE-2018-11007A Memory Leak issue was discovered in K7Computing K7AntiViru…5.5
- CVE-2018-11008An Incorrect Access Control issue was discovered in K7Comput…5.5
- CVE-2018-11009A Buffer Overflow issue was discovered in K7Computing K7Anti…7.8
- CVE-2018-11010A Buffer Overflow issue was discovered in K7Computing K7Anti…7.8
- CVE-2018-11011ruibaby Halo 0.0.2 has stored XSS via the commentAuthor fiel…
- CVE-2018-11012ruibaby Halo 0.0.2 has stored XSS via the loginName and logi…
- CVE-2018-11013Stack-based buffer overflow in the websRedirect function in …
- CVE-2018-11017The newVar_N function in decompile.c in libming through 0.4.…
- CVE-2018-11018An issue was discovered in PbootCMS v1.0.7. Cross-site reque…
Are you affected by CVE-2018-1101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
