PT-2021-9716 · Red Hat · Ansible Tower
Published
2021-05-27
·
Updated
2021-06-07
·
CVE-2020-14329
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible Tower versions prior to 3.7.2
Description
A data exposure flaw was found in Ansible Tower, where sensitive data can be exposed from the "/api/v2/labels/" endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this flaw is to confidentiality.
Recommendations
For versions prior to 3.7.2, update to version 3.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/api/v2/labels/" endpoint until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Tower