CVE-2020-14327
published 2021-05-27CVE-2020-14327: A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.25%
16.3th percentile
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ansible_tower | < 3.6.5 | 3.6.5 |
| redhat | ansible_tower | — | — |
| redhat | ansible_tower | >= 3.7.0 < 3.7.2 | 3.7.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hgxg-vrf8-v76v: A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3
ghsa_unreviewed·2022-05-24
CVE-2020-14327 [MEDIUM] CWE-918 GHSA-hgxg-vrf8-v76v: A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.
Red Hat
Tower: SSRF: Server Side Request Forgery on Credential
vendor_redhat·2020-07-14·CVSS 5.5
CVE-2020-14327 [MEDIUM] CWE-918 Tower: SSRF: Server Side Request Forgery on Credential
Tower: SSRF: Server Side Request Forgery on Credential
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.
A Server-side request forgery (SSRF) flaw was found in Tower. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusi
No detection rules found.
No public exploits indexed.
2021-05-27
Published