Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qmx-gcjw-jrg2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

EPSS

Процентиль: 55%
0.00329
Низкий

7.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.2
redhat
почти 7 лет назад

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

CVSS3: 7.2
nvd
почти 7 лет назад

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

CVSS3: 7.2
fstec
почти 7 лет назад

Уязвимость веб-интерфейса Ansible Tower средства управления конфигурациями Ansible, связанная с недостатками управления регистрационными данными, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 55%
0.00329
Низкий

7.2 High

CVSS3

Дефекты

CWE-200