Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14337

Опубликовано: 29 июл. 2020
Источник: redhat
CVSS3: 5.8

Описание

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.

Отчет

Ansible Tower 3.7.1 as well as previous versions are affected.

Меры по смягчению последствий

There is no mitigation for this issue.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1859139Tower: Named URLs allow for testing the presence or absence of objects

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
nvd
больше 5 лет назад

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.

github
больше 3 лет назад

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.

5.8 Medium

CVSS3