HIGH
ansible-tower: cross-site request forgery could result in credentials disclosure
Published Apr 30, 2019
8.8
HIGHCVSS 3.1
EPSS 1.52%
Description
A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins
Affected products
-
- Version 0.9.1 and earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins Ansible Tower Plugin | n/a |
|
- ≤ 0.9.1
No data.
CloudForms Management Engine 5
ansible-tower
Not affected
Red Hat Ansible Tower 3
ansible-tower
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | ansible-tower | Not affected | n/a |
| Red Hat Ansible Tower 3 | ansible-tower | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://www.openwall.com/lists/oss-security/2019/04/30/5 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108159 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2019-10310 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1829899 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5425 Advisory
- https://github.com/advisories/GHSA-vrvm-459q-j824 Advisory
- https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1355 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10310
- https://web.archive.org/web/20200227073756/http://www.securityfocus.com/bid/108159
- https://www.cve.org/CVERecord?id=CVE-2019-10310
- https://www.jenkins.io/security/advisory/2019-04-30/#SECURITY-1355%20(1)
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0786 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2019/04/30/5 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| http://www.securityfocus.com/bid/108159 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2019-10310 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1829899 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5425 | Advisory | |
| https://github.com/advisories/GHSA-vrvm-459q-j824 | Advisory | |
| https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1355 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10310 | ||
| https://web.archive.org/web/20200227073756/http://www.securityfocus.com/bid/108159 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-10310 | ||
| https://www.jenkins.io/security/advisory/2019-04-30/#SECURITY-1355%20(1) | ||
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0786 | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jenkins
Published Apr 30, 2019
Updated Aug 4, 2024
Reserved Mar 29, 2019
Link CVE-2019-10310
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-5425 GHSA-VRVM-459Q-J824 Assigner jenkins
Published Apr 30, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-5425