File Permissions Flaw in Ansible Tower by Red Hat
CVE-2019-19341
5.9MEDIUM
What is CVE-2019-19341?
A vulnerability exists in Ansible Tower versions prior to 3.6.2, where files in the '/var/backup/tower' directory are left world-readable. This includes critical data such as the SECRET_KEY and database backups. Any user with access to the server and knowledge of backup schedules can potentially retrieve all stored credentials, which poses a significant security risk.
Affected Version(s)
Tower all ansible_tower versions 3.6.x before 3.6.2