#VU22998 Cleartext storage of sensitive information in Ansible Tower - CVE-2019-14890
Published: November 26, 2019
Ansible Tower
Red Hat Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the application return a list of all users and their passwords in clear text via the "/api/v2/config" URL when applying the Ansible Tower license. A remote low privileged attacker can gain access to passwords of all users of the application.