Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7r9-mwvj-rr98

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

EPSS

Процентиль: 12%
0.00041
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.3
redhat
больше 5 лет назад

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

CVSS3: 3.3
nvd
больше 4 лет назад

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

EPSS

Процентиль: 12%
0.00041
Низкий

Дефекты

CWE-200