← Vulnerability feed

Vulnerability record · CVE-2017-12148 · published 27 July 2018

CVE-2017-12148: Redhat ansible tower improper input validation vulnerability

Redhat · Ansible Tower

A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by Tower, modifies the checked out SCM repository to add git hooks. These git hooks could, in turn, cause arbitrary command and code execution as the user Tower runs as.

7.2 CVSS 3.0 High EPSS 1.7% · top 23.5% CWE-20 · Improper input validation
7.2CVSS 3.0 base score, v2 9.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by Tower, modifies the checked out SCM repository to add git hooks. These git hooks could, in turn, cause arbitrary command and code execution as the user Tower runs as.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-5418Ruby on Rails Action View file content disclosure via crafted Accept headersAction View in Ruby on Rails fails to properly handle specially crafted Accept headers, allowing arbitrary files on the target filesystem to be read.…KEVEPSS 99%analysed9.8CVE-2018-16879Redhat ansible tower missing encryption vulnerabilityAnsible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging cel…EPSS 1.1%9.8CVE-2018-17456Git recursive clone argument injection enables remote code executionGit versions before the fixed releases mishandle a .gitmodules URL field that begins with a '-' character during recursive 'git clone' of a superproj…EPSS 97%analysed9.8CVE-2015-9262Debian linux memory buffer overflow vulnerability_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a…EPSS 5.7%9.8CVE-2018-12910Gnome libsoup out-of-bounds read vulnerabilityThe get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.EPSS 4.2%9.8CVE-2018-1000544Rubyzip project rubyzip link following vulnerabilityrubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …EPSS 4.4%9.8CVE-2018-7750Paramiko improper authentication vulnerabilitytransport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…EPSS 27%9.1CVE-2020-14325Redhat cloudforms vulnerabilityRed Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2017-12148), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.