CVE-2019-3869

Impact:
Moderate
Public Date:
2019-03-26
CWE:
CWE-214
Bugzilla:
1688508: CVE-2019-3869 Tower: credentials leaked through environment variables
When running Tower on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

Find out more about CVE-2019-3869 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.2
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Ansible Tower 3 for RHEL 7 ansible-tower-server Affected

Acknowledgements

Red Hat would like to thank Chris Bertsch (FactSet Research Systems Inc) for reporting this issue.

External References

Last Modified