cbcvebase.

Redhat Ansible Tower vulnerabilities

63 known vulnerabilities affecting redhat/ansible_tower.

Total CVEs
63
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH22MEDIUM31LOW6

Vulnerabilities

Page 3 of 4
CVE-2019-19341P4MEDIUMCVSS 5.5≥ 3.6.0, < 3.6.22019-12-19
CVE-2019-19341 [MEDIUM] CWE-732 CVE-2019-19341: A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' a A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest th
nvd
CVE-2018-14679P4MEDIUMCVSS 6.5v3.32018-07-28
CVE-2018-14679 [MEDIUM] CWE-193 CVE-2018-14679: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
nvd
CVE-2018-10768P4MEDIUMCVSS 6.5v3.32018-05-06
CVE-2018-10768 [MEDIUM] CWE-476 CVE-2018-10768: There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubun There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
nvd
CVE-2019-19342P4MEDIUMCVSS 5.3≥ 3.5.0, < 3.5.4≥ 3.6.0, < 3.6.22019-12-19
CVE-2019-19342 [MEDIUM] CWE-209 CVE-2019-19342: A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websock A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial password disclose will occur in plaintext. An attacker could easily guess
nvd
CVE-2021-3447P4MEDIUMCVSS 5.5fixed in 3.8.22021-04-01
CVE-2021-3447 [MEDIUM] CWE-532 CVE-2021-3447: A flaw was found in several ansible modules, where parameters containing credentials, such as secret A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode. These parameters were not protected by the no_log feature. An attacker can take advantage of this information to steal th
nvd
CVE-2020-14327P4MEDIUMCVSS 5.5fixed in 3.6.5≥ 3.7.0, < 3.7.2+1 more2021-05-27
CVE-2020-14327 [MEDIUM] CWE-918 CVE-2020-14327: A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and be A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature
nvd
CVE-2020-10782P4MEDIUMCVSS 6.5v3.7.02020-06-18
CVE-2020-10782 [MEDIUM] CWE-200 CVE-2020-10782: An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable permissions. The highest threat from this vulnerability is to confidentiality. This is fixed in Ansible version 3.
nvd
CVE-2019-14858P4MEDIUMCVSS 5.5≥ 3.0, ≤ 3.5.02019-10-14
CVE-2019-14858 [MEDIUM] CWE-117 CVE-2019-14858: A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a mo A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields wi
nvd
CVE-2020-1746P4MEDIUMCVSS 5.0≥ 3.4.0, ≤ 3.4.5≥ 3.5.0, ≤ 3.5.5+1 more2020-05-12
CVE-2020-1746 [MEDIUM] CWE-200 CVE-2020-1746: A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8 A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used. The issue discloses the LDAP bind password to stdout or a log file if
nvd
CVE-2020-10691P4MEDIUMCVSS 5.2v3.02020-04-30
CVE-2020-10691 [MEDIUM] CWE-22 CVE-2020-10691: An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when runnin An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.
nvd
CVE-2020-1733P4MEDIUMCVSS 5.0≤ 3.3.4≥ 3.3.5, ≤ 3.4.5+2 more2020-03-11
CVE-2020-1733 [MEDIUM] CWE-377 CVE-2020-1733: A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the d
nvd
CVE-2020-10744P4MEDIUMCVSS 5.0≥ 3.4.0, ≤ 3.4.5≥ 3.5.0, ≤ 3.5.6+1 more2020-05-15
CVE-2020-10744 [MEDIUM] CWE-377 CVE-2020-10744: An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary direct An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansib
nvd
CVE-2020-1740P4MEDIUMCVSS 4.7≤ 3.3.4≥ 3.3.5, ≤ 3.4.5+2 more2020-03-16
CVE-2020-1740 [MEDIUM] CWE-377 CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing sec
nvd
CVE-2018-0495P4MEDIUMCVSS 4.7v3.32018-06-13
CVE-2018-0495 [MEDIUM] CWE-203 CVE-2018-0495: Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA si Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access t
nvd
CVE-2017-18267P4MEDIUMCVSS 5.5v3.32018-05-10
CVE-2017-18267 [MEDIUM] CWE-835 CVE-2017-18267: The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote atta The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
nvd
CVE-2020-1735P4MEDIUMCVSS 4.6≤ 3.3.4≥ 3.3.5, ≤ 3.4.5+2 more2020-03-16
CVE-2020-1735 [MEDIUM] CWE-22 CVE-2020-1735: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept th A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
nvd
CVE-2020-10697P4MEDIUMCVSS 4.4fixed in 3.4.6≥ 3.5.0, < 3.5.6+2 more2021-05-27
CVE-2020-10697 [MEDIUM] CWE-862 CVE-2020-10697: A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in the worst-case scenario, it can reduce the Tower performance, for which me
nvd
CVE-2020-1739P4LOWCVSS 3.9≤ 3.3.4≥ 3.4.0, ≤ 3.4.5+2 more2020-03-12
CVE-2020-1739 [LOW] CWE-200 CVE-2020-1739: A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password i A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
nvd
CVE-2020-1738P4LOWCVSS 3.9≤ 3.3.4≥ 3.3.5, ≤ 3.4.5+2 more2020-03-16
CVE-2020-1738 [LOW] CWE-88 CVE-2020-1738: A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
nvd
CVE-2020-14329P4LOWCVSS 3.3fixed in 3.7.2vansible_tower 3.7.22021-05-27
CVE-2020-14329 [LOW] CWE-200 CVE-2020-14329: A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can b A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.
nvd