CVE-2020-14337: Medium severity red hat ansible tower vulnerability
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
Other sources
Ansible Tower automatically associates an alias to a user's email in the API. This means that an attacker can query or search for a user based on their email address. Because of this, it is possible to check and see if an arbitrary user exists.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14337?
CVE-2020-14337 is a data exposure flaw in Tower where sensitive data is revealed from the HTTP return error codes.
How does CVE-2020-14337 affect Redhat Ansible Tower?
CVE-2020-14337 affects Redhat Ansible Tower versions 3.0.0, 3.7.2, and 3.8.0.
How can an attacker exploit CVE-2020-14337?
An unauthenticated, remote attacker can exploit CVE-2020-14337 to retrieve pages from the default organization and verify existing usernames.
What is the severity of CVE-2020-14337?
The severity of CVE-2020-14337 is medium with a CVSS score of 5.8.
How can I mitigate the vulnerability described in CVE-2020-14337?
To mitigate CVE-2020-14337, it is recommended to update Redhat Ansible Tower to versions 3.7.2 or 3.8.0.