QID 14013

Date Published: 2022-01-18

QID 14013: Ansible Tower Security Update 3.8.1 Multiple Vulnerabilities

Ansible Tower by Red Hat helps you scale IT automation, manage complex deployments and speed productivity.

CVE-2019-20372: NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

Affected Versions:
Ansible Tower 3.6.0 to 3.6.6
Ansible Tower 3.7.0 to 3.7.4
Ansible Tower 3.8.0

QID Detection Logic:(Unauthenticated)
This QID checks the vulnerable Ansible Tower version installed on the target by checking the response of /api/v1/ping/?format=json.

An attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customer are advised to download Ansible Tower version 3-7-5,3-6-7 and 3-8-1 for remediation of this issue.
    For more information visit Ansible Tower .

    CVEs related to QID 14013

    Software Advisories
    Advisory ID Software Component Link
    Ansible Tower URL Logo docs.ansible.com/ansible-tower/latest/html/release-notes/relnotes.html#ansible-tower-version-3-8-1
    Ansible Tower Version 3.6.7 URL Logo docs.ansible.com/ansible-tower/latest/html/release-notes/relnotes.html#ansible-tower-version-3-6-7
    Ansible Tower Version 3.7.4 URL Logo docs.ansible.com/ansible-tower/latest/html/release-notes/relnotes.html#ansible-tower-version-3-7-5