PT-2019-4198 · Red Hat · Ansible Tower

Published

2019-11-26

·

Updated

2019-12-17

·

CVE-2019-14890

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ansible Tower versions prior to 3.6.1
Description A vulnerability allows an attacker with low privilege to retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database. This issue is related to the unencrypted storage of sensitive information in the /api/v2/config endpoint. Exploitation of this issue may allow an attacker to gain unauthorized access to application user passwords.
Recommendations For Ansible Tower versions prior to 3.6.1, update to version 3.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /api/v2/config endpoint to minimize the risk of exploitation. Avoid using the RHSM credentials in the affected API endpoint until the issue is resolved.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04794
CVE-2019-14890

Affected Products

Ansible Tower