CVE-2016-7070: Red Hat Ansible Tower
High severity, CVSS 8.0. EPSS: 0.6% chance of exploitation in the next 30 days.
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.
Affected products
- Red Hat Ansible Tower: before 3.0.3 (fixed in 3.0.3)
Published 2018-09-11. Last modified 2026-06-17.