Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-14329

Опубликовано: 27 мая 2021
Источник: nvd
CVSS3: 3.3
CVSS2: 2.1
EPSS Низкий

Описание

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
Версия до 3.7.2 (исключая)

EPSS

Процентиль: 12%
0.00041
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.3
redhat
больше 5 лет назад

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

github
больше 3 лет назад

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

EPSS

Процентиль: 12%
0.00041
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200