Tower: security channel is not set properly for AMPQ connection
Published Jan 3, 2019
9.8
CRITICALCVSS 3.1
EPSS 1.11%
Description
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
Affected products
- Vendor n/a Product Tower Defaultn/a
- Version 3.3.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Tower | n/a |
|
- < 3.3.3
No data.
CloudForms Management Engine 5
ansible-tower
Not affected
Red Hat Ansible Tower 3
ansible-tower-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | ansible-tower | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible-tower-server | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat CloudForms versions 4.5 and 4.6 ship an ansible-tower which correctly sets the security channel by default. Red Hat CloudForms version 4.7 ships ansible-tower 3.3.3 which already contains the fix.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.11% (0.01110) | 64.68th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.11% (0.01110) | 64.44th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.24% (0.00235) | 62.01th | v3 (v2023.03.01) |
| May 26, 2024 | 0.24% (0.00235) | 61.52th | v3 (v2023.03.01) |
| Feb 29, 2024 | 0.25% (0.00246) | 63.85th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.25% (0.00246) | 61.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00176) | 52.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.78% (0.00777) | 21.50th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.78% (0.00777) | 0.00th | v1 |
References (6)
- http://www.securityfocus.com/bid/106310 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-16879 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1658394 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16879 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16879
- https://www.cve.org/CVERecord?id=CVE-2018-16879
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106310 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-16879 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1658394 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16879 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-16879 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-16879 |
Change history (0)
No recorded changes yet.