ZeroHour

CVE-2019-14890

CVSS 3.1
8.4 high
EPSS
<1%p15
Published
()
Modified
Description

A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.

Vendors
redhat
Products
ansible tower
Weakness
CWE-312
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.