RHSA-2020:5249: Moderate: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container
Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) Improved Ansible Tower's web service configuration to allow for processing more simultaneous HTTP(s) requests by default Updated several dependencies of Ansible Tower's User Interface to address (CVE-2020-7720, CVE-2020-7743, CVE-2020-7676) Updated to the latest version of python-psutil to address CVE-2019-18874 Added several optimizations to improve performance for a variety of high-load simultaneous job launch use cases Fixed workflows to no longer prevent certain users from being able to edit approval nodes Fixed confusing behavior for social auth logins across distinct browser tabs Fixed launching of Job Templates that use prompt-at-launch Ansible Vault credentials
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2020:5249?
RHSA-2020:5249 addresses two jQuery vulnerabilities identified as CVE-2020-11022 and CVE-2020-11023.
What improvements does RHSA-2020:5249 provide for Ansible Tower?
The update improves Ansible Tower's web service configuration to handle more simultaneous HTTP(s) requests by default.
What is the risk associated with the vulnerabilities fixed in RHSA-2020:5249?
The vulnerabilities fixed in RHSA-2020:5249 could potentially allow for cross-site scripting attacks if left unaddressed.
How can I ensure my Ansible Tower is updated with the fixes from RHSA-2020:5249?
You can update your Ansible Tower installation by applying the latest security patches provided in RHSA-2020:5249.
What versions of Ansible Tower are affected by RHSA-2020:5249?
RHSA-2020:5249 affects all supported versions of Red Hat Ansible Tower that utilize the patched jQuery libraries.