Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat Ansible Tower
APPRedhat< 3.3.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
Related vulnerabilities
CVE-2018-17456CRITICAL9.8PL ✓same product
RCE w Git przez złośliwy URL w pliku .gitmodules podczas klonowania
CVE-2015-9262CRITICAL9.8PL ✓same product
Przepełnienie bufora sterty w libXcursor umożliwiające RCE lub DoS
CVE-2018-12910CRITICAL9.8PL ✓same product
Podatność out-of-bounds read w libsoup przez pustą nazwę hosta
CVE-2021-4112HIGH8.8same product
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This f...
CVE-2021-3583HIGH7.1same product
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occ...