Total vulnerabilities in the database
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
Software | From | Fixed in |
---|---|---|
redhat / ansible_tower | - | 3.3.5 |
redhat / ansible_tower | 3.4.0 | 3.4.3 |