CVE-2019-3869
published 2019-03-28CVE-2019-3869: When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious…
PriorityP339high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.29%
67.0th percentile
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | tower | — | — |
| red_hat | tower | — | — |
| redhat | ansible_tower | < 3.3.5 | 3.3.5 |
| redhat | ansible_tower | >= 3.4.0 < 3.4.3 | 3.4.3 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qmx-gcjw-jrg2: When running Tower before 3
ghsa_unreviewed·2022-05-13
CVE-2019-3869 [HIGH] CWE-200 GHSA-9qmx-gcjw-jrg2: When running Tower before 3
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
Red Hat
Tower: credentials leaked through environment variables
vendor_redhat·2019-03-26·CVSS 7.2
CVE-2019-3869 [HIGH] CWE-214 Tower: credentials leaked through environment variables
Tower: credentials leaked through environment variables
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
When running Tower on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
No detection rules found.
No public exploits indexed.
2019-03-28
Published