Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-785w-m3xw-jfp8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

An attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

An attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

EPSS

Процентиль: 5%
0.00023
Низкий

8.4 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 8.4
redhat
около 6 лет назад

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

CVSS3: 8.4
nvd
около 6 лет назад

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

CVSS3: 8.4
fstec
около 6 лет назад

Уязвимость компонента «/api/v2/config» консоли управления Red Hat Ansible Tower, позволяющая нарушителю получить несанкционированный доступ к паролям пользователей приложения

EPSS

Процентиль: 5%
0.00023
Низкий

8.4 High

CVSS3

Дефекты

CWE-312