SB2018122606 - Security restrictions bypass in Ansible Tower



SB2018122606 - Security restrictions bypass in Ansible Tower

Published: December 20, 2018 Updated: December 26, 2018

Security Bulletin ID SB2018122606
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2018-16879)

The vulnerability allows an adjacent attacker to bypass security restrictions.

The vulnerability exists due to security channel is not set properly for AMPQ connection. An adjacent attacker can bypass security restrictions and gain access to potentially sensitive information or cause the service to crash.


Remediation

Install update from vendor's website.