PT-2021-9169 · Red Hat · Ansible Tower

Published

2021-05-27

·

Updated

2022-06-15

·

CVE-2020-10698

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ansible Tower versions prior to 3.6.4 Ansible Tower versions prior to 3.5.6 Ansible Tower versions prior to 3.4.6
Description A flaw in Ansible Tower allows an attacker to access the stdout of executed jobs from other organizations, potentially disclosing sensitive data. However, critical data should be protected by the no log flag when debugging is enabled.
Recommendations For Ansible Tower versions prior to 3.6.4, update to version 3.6.4 or later. For Ansible Tower versions prior to 3.5.6, update to version 3.5.6 or later. For Ansible Tower versions prior to 3.4.6, update to version 3.4.6 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10698

Affected Products

Ansible Tower