CyberSec.Space Logo
Back to CVE Browser

CVE-2018-10884

HIGH
8.8
CVSS Severity Score
EPSS Score0.1490%
EPSS Percentile21.56th
PublishedAug 22, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.

Affected Platforms (CPE)

πŸ“¦
Redhat

Ansible Tower

>= 3.1.0 and <= 3.1.8
πŸ“¦
Redhat

Ansible Tower

>= 3.2.0 and <= 3.2.6

References & Advisories

Related Vulnerabilities

CVE-2018-10884 Detail & Impact Analysis | CVSS 8.8 (HIGH) | Cyber-Sec.Space | Cyber-Sec.Space