When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
| Software | From | Fixed in |
|---|---|---|
| redhat / ansible_tower | - | 3.3.5 |
| redhat / ansible_tower | 3.4.0 | 3.4.3 |