Redhat Ansible Tower vulnerabilities
63 known vulnerabilities affecting redhat/ansible_tower.
Total CVEs
63
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH22MEDIUM31LOW6
Vulnerabilities
Page 1 of 4
CVE-2020-10684P1HIGHCVSS 7.1Exploited≤ 3.3.5≥ 3.5.0, ≤ 3.5.5+1 more2020-03-24
CVE-2020-10684 [HIGH] CWE-94 CVE-2020-10684: A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansibl
nvd
CVE-2018-17456P1CRITICALCVSS 9.8PoCv3.32018-10-06
CVE-2018-17456 [CRITICAL] CWE-88 CVE-2018-17456: Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
nvd
CVE-2018-1000805P3HIGHCVSS 8.8v3.32018-10-08
CVE-2018-1000805 [HIGH] CWE-863 CVE-2018-1000805: Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Contr
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
nvd
CVE-2018-1104P3HIGHCVSS 8.8≤ 3.2.32018-05-02
CVE-2018-1104 [HIGH] CWE-20 CVE-2018-1104: Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
nvd
CVE-2019-19340P3HIGHCVSS 8.2≥ 3.5.0, < 3.5.3≥ 3.6.0, < 3.6.22019-12-19
CVE-2019-19340 [HIGH] CWE-1188 CVE-2019-19340: A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enablin
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
nvd
CVE-2015-9262P3CRITICALCVSS 9.8v3.32018-08-01
CVE-2015-9262 [CRITICAL] CWE-119 CVE-2015-9262: _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause deni
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
nvd
CVE-2017-12148P3HIGHCVSS 7.2fixed in 3.1.5fixed in 3.2.02018-07-27
CVE-2017-12148 [HIGH] CWE-20 CVE-2017-12148: A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tow
A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by Tower, modifies the checked out SCM
nvd
CVE-2021-4112P3HIGHCVSS 8.8v3.02022-08-25
CVE-2021-4112 [HIGH] CWE-552 CVE-2021-4112: A flaw was found in ansible-tower where the default installation is vulnerable to job isolation esca
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
nvd
CVE-2021-20228P3HIGHCVSS 7.5v3.02021-04-29
CVE-2021-20228 [HIGH] CWE-200 CVE-2021-20228: A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2018-1101P3HIGHCVSS 7.2fixed in 3.2.42018-05-02
CVE-2018-1101 [HIGH] CWE-266 CVE-2018-1101: Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administr
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
nvd
CVE-2018-12910P3CRITICALCVSS 9.8v3.32018-07-05
CVE-2018-12910 [CRITICAL] CWE-125 CVE-2018-12910: The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
nvd
CVE-2018-14681P3HIGHCVSS 8.8v3.32018-07-28
CVE-2018-14681 [HIGH] CWE-787 CVE-2018-14681: An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KW
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
nvd
CVE-2019-14890P3HIGHCVSS 8.4v3.6.02019-11-26
CVE-2019-14890 [HIGH] CWE-312 CVE-2019-14890: A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could r
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.
nvd
CVE-2020-1737P3HIGHCVSS 7.8≤ 3.3.4≥ 3.4.0, ≤ 3.4.5+2 more2020-03-09
CVE-2020-1737 [HIGH] CWE-22 CVE-2020-1737: A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Ex
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as the extracted file(s) are not checked if they belong to the destination folder. An attacker could take advantage of this flaw by crafting an archive anywhere in the file system, using a path traversal. This i
nvd
CVE-2018-14682P3HIGHCVSS 8.8v3.32018-07-28
CVE-2018-14682 [HIGH] CWE-193 CVE-2018-14682: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
nvd
CVE-2018-1060P3HIGHCVSS 7.5v3.32018-06-18
CVE-2018-1060 [HIGH] CWE-20 CVE-2018-1060: python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic bac
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
nvd
CVE-2018-1061P3HIGHCVSS 7.5v3.32018-06-19
CVE-2018-1061 [HIGH] CWE-20 CVE-2018-1061: python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic bac
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
nvd
CVE-2018-16879P3CRITICALCVSS 9.8fixed in 3.3.32019-01-03
CVE-2018-16879 [CRITICAL] CWE-311 CVE-2018-16879: Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
nvd
CVE-2019-3869P3HIGHCVSS 7.2fixed in 3.3.5≥ 3.4.0, < 3.4.32019-03-28
CVE-2019-3869 [HIGH] CWE-214 CVE-2019-3869: When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to p
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
nvd
CVE-2018-10884P3HIGHCVSS 8.8≥ 3.1.0, ≤ 3.1.8≥ 3.2.0, ≤ 3.2.62018-08-22
CVE-2018-10884 [HIGH] CWE-352 CVE-2018-10884: Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.
nvd
1 / 4Next →