A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7070 | issue tracking vendor advisory |
https://docs.ansible.com/ansible-tower/3.0.3/html/upgrade-migration-guide/release_notes.html | release notes vendor advisory |