redhat ansible-tower CVE-2019-3869 is a vulnerability in Red Hat Ansible Tower
Published on March 28, 2019

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

NVD

Weakness Type

Invocation of Process Using Visible Sensitive Information

A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system. Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as credentials, it might allow other users to launch an attack against the software or related resources.


Products Associated with CVE-2019-3869

Want to know whenever a new CVE is published for Red Hat Ansible Tower? stack.watch will email you.

 

Affected Versions

Red Hat Tower:

Exploit Probability

EPSS
0.33%
Percentile
55.50%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.