CVE-2018-16879
published 2019-01-03CVE-2018-16879: Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery…
PriorityP338critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.11%
62.2th percentile
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | ncurses | >= 0 < 5.9+20140118-1ubuntu1+esm2 | 5.9+20140118-1ubuntu1+esm2 |
| gnu | ncurses | >= 0 < 6.0+20160213-1ubuntu1+esm2 | 6.0+20160213-1ubuntu1+esm2 |
| redhat | ansible_tower | < 3.3.3 | 3.3.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.3HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Tower: security channel is not set properly for AMPQ connection
vendor_redhat·2018-12-20·CVSS 9.8
CVE-2018-16879 [CRITICAL] CWE-311 Tower: security channel is not set properly for AMPQ connection
Tower: security channel is not set properly for AMPQ connection
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
Tower does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
Statement: Red Hat CloudForms versions 4.5 and 4.6 ship an ansible-tower which correctly sets the security cha
OSV
ncurses vulnerabilities
osv·2022-06-14·CVSS 7.8
CVE-2017-16879 ncurses vulnerabilities
ncurses vulnerabilities
Hosein Askari discovered that ncurses was incorrectly performing
memory management operations when dealing with long filenames while
writing structures into the file system. An attacker could possibly
use this issue to cause a denial of service or execute arbitrary
code. (CVE-2017-16879)
Chung-Yi Lin discovered that ncurses was incorrectly handling access
to invalid memory areas when parsing terminfo or termcap entries where
the use-name had invalid syntax. An attacker could possibly use this
issue to cause a denial of service. (CVE-2018-19211)
It was discovered that ncurses was incorrectly performing bounds
checks when processing invalid hashcodes. An attacker could possibly
use this issue to cause a denial of service or to expose sensitive
information. (CVE-201
GHSA
GHSA-xw9p-c763-93fq: Ansible Tower before version 3
ghsa_unreviewed·2022-05-13
CVE-2018-16879 [CRITICAL] CWE-311 GHSA-xw9p-c763-93fq: Ansible Tower before version 3
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
No detection rules found.
No public exploits indexed.
2019-01-03
Published