Data Exposure Vulnerability in Ansible Tower by Red Hat
CVE-2019-14890

8.4HIGH

Key Information:

Vendor

[unknown]

Status
Vendor
CVE Published:
26 November 2019

What is CVE-2019-14890?

A significant data exposure vulnerability was identified in Ansible Tower versions prior to 3.6.1, which allows attackers with limited privileges to access sensitive information, including usernames and passwords. This information is stored in plain text within the database at the '/api/v2/config' endpoint when modifying the Ansible Tower license. It is crucial for users to update their installations to mitigate the risk of unauthorized data retrieval.

Affected Version(s)

Tower 3.6.1

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.