A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14890 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-11-26T06:46:17

Updated: 2019-12-02T14:17:50

Reserved: 2019-08-10T00:00:00


Link: CVE-2019-14890

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-11-26T07:15:11.163

Modified: 2019-12-17T18:07:27.007


Link: CVE-2019-14890

JSON object: View

cve-icon Redhat Information

No data.

CWE