9.8
CVSSv3

CVE-2018-16879

Published: 03/01/2019 Updated: 03/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible tower

Vendor Advisories

Tower does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files ...