Tower: RHSM username and password exposed after license application
Published Nov 26, 2019
8.4
HIGHCVSS 3.1
EPSS 0.24%
Description
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.
Affected products
- Vendor n/a Product Tower Defaultn/a
- Version 3.6.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Tower | n/a |
|
- 3.6.0
No data.
Red Hat Ansible Tower 3.6 for RHEL 7
ansible-tower-36/ansible-tower:3.6.1-1
Fixed · RHSA-2019:3958
CloudForms Management Engine 5
ansible-tower
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.6 for RHEL 7 | ansible-tower-36/ansible-tower:3.6.1-1 | Fixed | RHSA-2019:3958 |
| CloudForms Management Engine 5 | ansible-tower | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Ansible Tower 3.6.0 is affected, but Ansible Tower 3.5, 3.4, and 3.3 are not vulnerable as they do not include the new RHSM. CloudForms 5.9 and 5.10 are not vulnerable as they do not use Ansible Tower 3.6.0.
Red Hat mitigation
There is no mitigation for this issue since this issue happens when Red Hat license is applied.
References (6)
- https://access.redhat.com/security/cve/CVE-2019-14890 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1773622 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14890 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5998 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14890
- https://www.cve.org/CVERecord?id=CVE-2019-14890
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-14890 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1773622 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14890 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5998 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-14890 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-14890 |
Change history (0)
No recorded changes yet.