CVE-2017-7528: CRLF Injection
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7528?
CVE-2017-7528 is a vulnerability in Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 that allows CRLF Injection.
How severe is CVE-2017-7528?
CVE-2017-7528 has a severity rating of 6.5 (medium).
How does the vulnerability in Ansible Tower affect Red Hat CloudForms Management Engine 5?
The vulnerability in Ansible Tower allows internal servers to deploy other systems using a callback, potentially compromising Red Hat CloudForms Management Engine 5.
What is the affected software?
The affected software includes Red Hat Ansible Tower and Red Hat CloudForms Management Engine 5.0.
How can I fix CVE-2017-7528?
To fix CVE-2017-7528, it is recommended to apply the necessary patches and updates provided by Red Hat.