Information disclosure in Ansible Tower - CVE-2019-3869

 

Information disclosure in Ansible Tower - CVE-2019-3869

Published: March 28, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31137
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-3869
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Red Hat Inc.
Affected software:
Ansible Tower

Detailed vulnerability description

The vulnerability allows a remote privileged user to execute arbitrary code.

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.


How to mitigate CVE-2019-3869

Install update from vendor's website.

Sources