CVE-2018-1101: Red Hat Ansible Tower
High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
Affected products
- Red Hat Ansible Tower: before 3.2.4 (fixed in 3.2.4)
- Red Hat Cloudforms: version 4.5 only; version 4.6 only
Published 2018-05-02. Last modified 2026-06-17.