CVE-2021-4112
Ansible Tower vulnerability analysis and mitigation

Overview

A security vulnerability (CVE-2021-4112) was discovered in ansible-tower's default installation, making it susceptible to job isolation escape. The vulnerability enables attackers to escalate privileges from a low-privileged user to an AWX user from outside the isolated environment. This vulnerability affects Red Hat Ansible Automation Platform 2.0/2.1, Red Hat Enterprise Linux 8.0, and Ansible Tower 3.0 (NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The flaw is categorized under CWE-552 (Files or Directories Accessible to External Parties). The vulnerability allows attackers to bypass CVE-2021-20253 by sending a mail to the AWX user, utilizing postfix to create a folder owned by AWX, and then placing a binary in that folder that enables privilege escalation outside the isolation jail (Red Hat Bugzilla).

Impact

The vulnerability enables privilege escalation from a low-privileged user to an AWX user, allowing the attacker to escape from the isolated environment. This poses a significant security risk as it could lead to unauthorized access and control over the Ansible automation environment (Red Hat Advisory).

Exploitability

The vulnerability requires local access with low privileges and no user interaction for exploitation. The attack complexity is low, making it relatively straightforward to exploit once an attacker has the necessary local access (NVD).

Mitigation and workarounds

Red Hat has released security updates to address this vulnerability. For Ansible Tower 3.8, the fix is included in ansible-tower 3.8.5-2 and ansible-runner 1.4.7-2 RPMs, which are part of ansible-tower-setup-bundle-3.8.5-2.tar.gz/ansible-automation-platform-setup-bundle-1.2.6-2.tar.gz. Users should apply the security updates through their platform installer (setup.sh) (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Ansible Tower vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-4112HIGH8.8
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesAug 25, 2022
CVE-2021-3583HIGH7.1
  • Ansible Tower logoAnsible Tower
  • python3-hwdata
NoYesSep 22, 2021
CVE-2020-14327MEDIUM5.5
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021
CVE-2020-14329LOW3.3
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021
CVE-2020-14328LOW3.3
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management