PT-2019-15816 · Red Hat · Ansible Tower

Borja Tarraso

·

Published

2019-12-19

·

Updated

2023-01-31

·

CVE-2019-19341

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ansible Tower versions 3.6.x before 3.6.2
Description A flaw was found in Ansible Tower where files in '/var/backup/tower' are left world-readable. These files include both the SECRET KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest threat with this issue.
Recommendations For Ansible Tower versions 3.6.x before 3.6.2, update to version 3.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the '/var/backup/tower' directory to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2019-19341

Affected Products

Ansible Tower