Permissions, Privileges, and Access Controls in Ansible Tower - CVE-2016-7070
Published: September 11, 2018 / Updated: July 17, 2020
Ansible Tower
Detailed vulnerability description
The vulnerability allows a remote authenticated user to execute arbitrary code.
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.