Jenkins Ansible Tower vulnerabilities

3 known vulnerabilities affecting jenkins/ansible_tower.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2019-10310HIGHCVSS 8.8≤ 0.9.12019-04-30
CVE-2019-10310 [HIGH] CWE-352 CVE-2019-10310: A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credential
nvd
CVE-2019-10311HIGHCVSS 8.8≤ 0.9.12019-04-30
CVE-2019-10311 [HIGH] CWE-862 CVE-2019-10311: A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallatio A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credent
nvd
CVE-2019-10312MEDIUMCVSS 4.3≤ 0.9.12019-04-30
CVE-2019-10312 [MEDIUM] CWE-862 CVE-2019-10312: A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallatio A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
nvd