CVE-2017-7528

CWE-113CWE-935 documents5 sources
Severity
6.5MEDIUM
EPSS
0.1%
top 65.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateMay 13

Description

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:NExploitability: 0.9 | Impact: 4.2

Affected Packages2 packages

CVEListV5red_hat/ansible_towerAs shipped with Red Hat CloudForms Management Engine 5

🔴Vulnerability Details

2
GHSA
GHSA-qh6h-825q-q4mx: Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection2022-05-13
CVEList
CVE-2017-7528: Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection2018-08-22

📋Vendor Advisories

1
Red Hat
Tower: X-Forwarded-For header allows internal servers to deploy other systems (using callback)

💬Community

1
Bugzilla
CVE-2017-7528 Ansible Tower: X-Forwarded-For header allows internal servers to deploy other systems (using callback)2017-06-30
CVE-2017-7528 (MEDIUM CVSS 6.5) | Ansible Tower as shipped with Red H | cvebase.io