CVE-2018-1104: Red Hat Ansible Tower

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

Affected products

  • Red Hat Ansible Tower: up to and including 3.2.3
  • Red Hat Cloudforms: version 4.5 only; version 4.6 only

Published 2018-05-02. Last modified 2026-06-17.