First published: Tue Jul 21 2020(Updated: )
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Ansible Tower | =3.0.0 | |
redhat/ansible_tower | <3.7.2 | 3.7.2 |
redhat/ansible_tower | <3.8.0 | 3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14337 is a data exposure flaw in Tower where sensitive data is revealed from the HTTP return error codes.
CVE-2020-14337 affects Redhat Ansible Tower versions 3.0.0, 3.7.2, and 3.8.0.
An unauthenticated, remote attacker can exploit CVE-2020-14337 to retrieve pages from the default organization and verify existing usernames.
The severity of CVE-2020-14337 is medium with a CVSS score of 5.8.
To mitigate CVE-2020-14337, it is recommended to update Redhat Ansible Tower to versions 3.7.2 or 3.8.0.