PT-2021-9714 · Red Hat · Ansible Tower
Published
2021-05-27
·
Updated
2021-06-07
·
CVE-2020-14327
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible Tower versions prior to 3.6.5
Ansible Tower versions prior to 3.7.2
Description
A Server-side request forgery (SSRF) flaw was found in Ansible Tower. The flaw is exploited by supplying a URL that could lead to the server processing it, allowing the connection to internal services or the exposure of additional internal services. This is achieved by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.
Recommendations
For versions prior to 3.6.5, update to version 3.6.5 or later.
For versions prior to 3.7.2, update to version 3.7.2 or later.
As a temporary workaround, consider restricting access to the test feature of lookup credentials to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Tower