Back

HIGH

Tower: RHSM username and password exposed after license application

Published Nov 26, 2019

Description

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

Affected products

Remediation

Red Hat statement

Ansible Tower 3.6.0 is affected, but Ansible Tower 3.5, 3.4, and 3.3 are not vulnerable as they do not include the new RHSM. CloudForms 5.9 and 5.10 are not vulnerable as they do not use Ansible Tower 3.6.0.

Red Hat mitigation

There is no mitigation for this issue since this issue happens when Red Hat license is applied.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 26, 2019
Updated Aug 5, 2024
Reserved Aug 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 25, 2019
ENISA EUVD
Assigner redhat
Published Nov 26, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-5998