cbcvebase.
CVE-2018-16879
published 2019-01-03

CVE-2018-16879: Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery…

PriorityP338critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.11%
62.2th percentile
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

Affected

3 ranges
VendorProductVersion rangeFixed in
gnuncurses>= 0 < 5.9+20140118-1ubuntu1+esm25.9+20140118-1ubuntu1+esm2
gnuncurses>= 0 < 6.0+20160213-1ubuntu1+esm26.0+20160213-1ubuntu1+esm2
redhatansible_tower< 3.3.33.3.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.3HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.