Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw9p-c763-93fq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

EPSS

Процентиль: 46%
0.00229
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.3
redhat
больше 6 лет назад

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

CVSS3: 9.8
nvd
больше 6 лет назад

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

EPSS

Процентиль: 46%
0.00229
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-311