Vulnerability Details CVE-2021-4112
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2021-4112
-
cpe:2.3:a:redhat:ansible_automation_platform:2.0
-
cpe:2.3:a:redhat:ansible_automation_platform:2.1
-
cpe:2.3:a:redhat:ansible_automation_platform_early_access:2.0
-
cpe:2.3:a:redhat:ansible_automation_platform_text-only_advisories:-
-
cpe:2.3:a:redhat:ansible_tower:3.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0