cbcvebase.

Redhat Ansible Tower vulnerabilities

63 known vulnerabilities affecting redhat/ansible_tower.

Total CVEs
63
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH22MEDIUM31LOW6

Vulnerabilities

Page 4 of 4
CVE-2020-10698P4LOWCVSS 3.3fixed in 3.4.6≥ 3.5.0, < 3.5.6+1 more2021-05-27
CVE-2020-10698 [LOW] CWE-200 CVE-2020-10698: A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdo A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible data can be disclosed. However, critical data should not be disclosed, as it should be protected by the no_log flag when debugging is enabled. This flaw affects Ansible Tower v
nvd
CVE-2020-14328P4LOWCVSS 3.3fixed in 3.7.2vansible_tower 3.7.22021-05-27
CVE-2020-14328 [LOW] CWE-918 CVE-2020-14328: A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can b A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal services or exposing additional internal services and more particularly retrieving full details in case of error. The highest threat from this vulnerability i
nvd
CVE-2020-1736P4LOWCVSS 3.3≤ 3.3.4≥ 3.3.5, ≤ 3.4.5+3 more2020-03-16
CVE-2020-1736 [LOW] CWE-732 CVE-2020-1736: A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensiti
nvd
Redhat Ansible Tower vulnerabilities | cvebase