← Back

CVE-2021-20253

nvd nist
Published: Mar 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected (3)

1 product
Ansible Tower
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Before 3.6.7
From 3.7.0 to 3.7.5
From 3.8.0 to 3.8.2

References (2)

Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.