#VU24222 Incorrect default permissions in Ansible Tower - CVE-2019-19341
Published: January 13, 2020
Ansible Tower
Red Hat Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for the "/var/backup/tower" files that may contain both the SECRET_KEY and the database backup. A local user with access to the system can view contents of files and retrieve all credentials stored in Tower.