Permissions, Privileges, and Access Controls in Ansible Tower - CVE-2016-7070

 

Permissions, Privileges, and Access Controls in Ansible Tower - CVE-2016-7070

Published: September 11, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31217
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-7070
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Red Hat Inc.
Affected software:
Ansible Tower

Detailed vulnerability description

The vulnerability allows a remote authenticated user to execute arbitrary code.

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.


How to mitigate CVE-2016-7070

Install update from vendor's website.

Sources