7.2
CVSSv3

CVE-2019-3869

Published: 28/03/2019 Updated: 21/05/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

When running Tower prior to 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ansible tower

Vendor Advisories

Impact: Moderate Public Date: 2019-03-26 CWE: CWE-214 Bugzilla: 1688508: CVE-2019-3869 Tower: credentia ...