When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3869 Issue Tracking Patch Vendor Advisory
https://github.com/ansible/awx/pull/3505 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-03-28T13:04:59

Updated: 2019-03-28T13:04:59

Reserved: 2019-01-03T00:00:00


Link: CVE-2019-3869

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-03-28T14:29:00.307

Modified: 2020-05-21T15:41:31.540


Link: CVE-2019-3869

JSON object: View

cve-icon Redhat Information

No data.