CVE-2020-14337
published 2020-07-31CVE-2020-14337: A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote…
PriorityP431medium5.8CVSS 3.1
AVNACLPRNUINSCCLINAN
EPSS
1.49%
71.4th percentile
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ansible_tower | — | — |
| redhat | ansible_tower | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p8pw-f2qh-mrc2: A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes
ghsa_unreviewed·2022-05-24
CVE-2020-14337 [MEDIUM] GHSA-p8pw-f2qh-mrc2: A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
Red Hat
Tower: Named URLs allow for testing the presence or absence of objects
vendor_redhat·2020-07-29·CVSS 5.8
CVE-2020-14337 [MEDIUM] CWE-209 Tower: Named URLs allow for testing the presence or absence of objects
Tower: Named URLs allow for testing the presence or absence of objects
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
Statement: Ansible Tower 3.7.1 as well as previous versions are affected.
Mitigation: There is no mit
No detection rules found.
No public exploits indexed.
2020-07-31
Published