Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14890

Опубликовано: 25 нояб. 2019
Источник: redhat
CVSS3: 8.4

Описание

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

A flaw was found in Ansible Tower where the RHSM credentials are saved in plain text in the database that is available at '/api/v2/config' after applying the Ansible Tower license. Attackers with this information could log into RHSM and modify licenses and make other changes.

Отчет

Ansible Tower 3.6.0 is affected, but Ansible Tower 3.5, 3.4, and 3.3 are not vulnerable as they do not include the new RHSM. CloudForms 5.9 and 5.10 are not vulnerable as they do not use Ansible Tower 3.6.0.

Меры по смягчению последствий

There is no mitigation for this issue since this issue happens when Red Hat license is applied.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ansible-towerNot affected
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHSA-2019:395825.11.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=1773622Tower: RHSM username and password exposed after license application

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
около 6 лет назад

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

CVSS3: 8.4
github
больше 3 лет назад

An attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

CVSS3: 8.4
fstec
около 6 лет назад

Уязвимость компонента «/api/v2/config» консоли управления Red Hat Ansible Tower, позволяющая нарушителю получить несанкционированный доступ к паролям пользователей приложения

8.4 High

CVSS3