8.4
CVSSv3

CVE-2019-14890

Published: 26/11/2019 Updated: 17/12/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 8.4 | Impact Score: 5.8 | Exploitability Score: 2
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability was found in Ansible Tower prior to 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible tower 3.6.0

Vendor Advisories

Synopsis Critical: Red Hat Ansible Tower 361-1 - EL7 Container Type/Severity Security Advisory: Critical Topic Red Hat Ansible Tower 361-1 - EL7 Container Description Ansible Tower Version 361---------------------------- Fixed accidental disclosure of Red Hat username and password in ...