RHSA-2020:3328MediumCVSS 5.8
Red Hat Security Advisory: Red Hat Ansible Tower 3.7.2-1 - RHEL7 Container
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-14327 — Tower: SSRF: Server Side Request Forgery on Credential CVE-2020-14328 — Tower: SSRF: Server Side Request Forgery on webhooks CVE-2020-14329 — Tower: Sensitive Data Exposure on Label CVE-2020-14337 — Tower: Named URLs allow for testing the presence or absence of objects
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2020:3328
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856785
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1859139
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3328.json