QID 14013
Date Published: 2022-01-18
QID 14013: Ansible Tower Security Update 3.8.1 Multiple Vulnerabilities
Ansible Tower by Red Hat helps you scale IT automation, manage complex deployments and speed productivity.
CVE-2019-20372: NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Affected Versions:
Ansible Tower 3.6.0 to 3.6.6
Ansible Tower 3.7.0 to 3.7.4
Ansible Tower 3.8.0
QID Detection Logic:(Unauthenticated)
This QID checks the vulnerable Ansible Tower version installed on the target by checking the response of /api/v1/ping/?format=json.
An attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Solution
Customer are advised to download Ansible Tower version 3-7-5,3-6-7 and 3-8-1 for remediation of this issue.
For more information visit Ansible Tower .
For more information visit Ansible Tower .
Vendor References
- Ansible Tower -
docs.ansible.com/ansible-tower/latest/html/release-notes/relnotes.html#ansible-tower-version-3-8-1 - Ansible Tower Version 3.6.7 -
docs.ansible.com/ansible-tower/latest/html/release-notes/relnotes.html#ansible-tower-version-3-6-7 - Ansible Tower Version 3.7.4 -
docs.ansible.com/ansible-tower/latest/html/release-notes/relnotes.html#ansible-tower-version-3-7-5
CVEs related to QID 14013
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ansible Tower |
|
||
| Ansible Tower Version 3.6.7 |
|
||
| Ansible Tower Version 3.7.4 |
|