Advisory Published

RHSA-2020:5249: Moderate: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container

First published: Mon Nov 30 2020(Updated: )

<li> Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023)</li> <li> Improved Ansible Tower's web service configuration to allow for processing more simultaneous HTTP(s) requests by default</li> <li> Updated several dependencies of Ansible Tower's User Interface to address (CVE-2020-7720, CVE-2020-7743, CVE-2020-7676)</li> <li> Updated to the latest version of python-psutil to address CVE-2019-18874</li> <li> Added several optimizations to improve performance for a variety of high-load simultaneous job launch use cases</li> <li> Fixed workflows to no longer prevent certain users from being able to edit approval nodes</li> <li> Fixed confusing behavior for social auth logins across distinct browser tabs</li> <li> Fixed launching of Job Templates that use prompt-at-launch Ansible Vault credentials</li>

Affected SoftwareAffected VersionHow to fix
Red Hat Ansible

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What vulnerabilities are addressed in RHSA-2020:5249?

    RHSA-2020:5249 addresses two jQuery vulnerabilities identified as CVE-2020-11022 and CVE-2020-11023.

  • What improvements does RHSA-2020:5249 provide for Ansible Tower?

    The update improves Ansible Tower's web service configuration to handle more simultaneous HTTP(s) requests by default.

  • What is the risk associated with the vulnerabilities fixed in RHSA-2020:5249?

    The vulnerabilities fixed in RHSA-2020:5249 could potentially allow for cross-site scripting attacks if left unaddressed.

  • How can I ensure my Ansible Tower is updated with the fixes from RHSA-2020:5249?

    You can update your Ansible Tower installation by applying the latest security patches provided in RHSA-2020:5249.

  • What versions of Ansible Tower are affected by RHSA-2020:5249?

    RHSA-2020:5249 affects all supported versions of Red Hat Ansible Tower that utilize the patched jQuery libraries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203