CVE-2018-1104

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
02/05/2018
Last modified:
09/10/2019

Description

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* 3.2.3 (including)
cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:4.6:*:*:*:*:*:*:*