CVE-2019-19340: High severity red hat ansible tower vulnerability
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmqenablemanager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19340?
CVE-2019-19340 is a vulnerability found in Ansible Tower versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3.
How does CVE-2019-19340 affect Ansible Tower?
CVE-2019-19340 affects Ansible Tower by exposing the RabbitMQ management interface publicly when enabling RabbitMQ manager.
What is the severity rating of CVE-2019-19340?
The severity rating of CVE-2019-19340 is high with a CVSS score of 8.2.
How can I fix CVE-2019-19340 in Ansible Tower?
To fix CVE-2019-19340 in Ansible Tower, upgrade to version 3.6.2 or 3.5.3.
Where can I find more information about CVE-2019-19340?
More information about CVE-2019-19340 can be found at the following reference: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19340