#VU101828 Improper privilege management in django-ansible-base - CVE-2024-11483
Published: December 18, 2024
django-ansible-base
Red Hat Inc.
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper privilege management within the API endpoints that rely on ansible_base.oauth2_provider for OAuth2 authentication. A remote user can bypass OAuth2 scope restrictions on their tokens, escalating from read to write permissions.