Skip to main content

Vendor/product archive

redhat / ansible_tower CVEs

Beta · best-effort

64 CVEs tagged to redhat / ansible_tower4 Critical, 21 High, 32 Medium, 7 Low, 0 Unrated.

CVE-2020-14329

Published May 27, 2021

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-14328

Published May 27, 2021

A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connec…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-14327

Published May 27, 2021

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10709

Published May 27, 2021

A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10698

Published May 27, 2021

A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible d…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-10697

Published May 27, 2021

A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this ca…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20191

Published May 26, 2021

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker…

CVSS 5.5 · Medium

CVE-2021-20253

Published Mar 9, 2021

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the a…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14337

Published Jul 31, 2020

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10782

Published Jun 18, 2020

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10691

Published Apr 30, 2020

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file,…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 64 CVEsPage 1 of 3