Executive Summary

Summary
Title Red Hat Ansible Tower 3.3.5
Informations
Name RHSA-2019:0652 First vendor Publication 2019-03-26
Vendor RedHat Last vendor Modification 2019-03-26
Severity (Vendor) N/A Revision 01

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

Red Hat Ansible Tower 3.3.5

2. Description:

For a list of changes included in this release, please read the Ansible Tower Release Notes: https://docs.ansible.com/ansible-tower/latest/html/release-notes/index.html

3. Solution:

For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/ index.html

4. References:

https://access.redhat.com/security/cve/CVE-2018-5407 https://access.redhat.com/security/cve/CVE-2019-3835 https://access.redhat.com/security/cve/CVE-2019-3838 https://access.redhat.com/security/updates/classification/#moderate

5. Contact:

The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1

iQIVAwUBXJpWH9zjgjWX9erEAQg9NA//ebBrxCt3FFeYOU1qUTzEpjdQOEdOLWLK hxtz2zn/r6eanzbJkFuRkNFJKw5LzCS5oA1ByPh3x+TauVzb0cEmat6EGNNt4RAc tl7f7ELlpo8L9lwleVIPNUf7Qh5dKvKmAlmvXcuAKWZBOVe12ezwgjAAMEfiDc1U p/RfC3C8HMltjZ9f6VoEBj6+LEaEU7xXUIGzNEZa5CrEb6CHc6zKnt2MHDy6TjAT YuG6JxhhqoeHVkI2s7dARTzu4Wt7S3o9dATVXORa8mrDBSPlw+DPsGZwqNRO1ucj mlBXNnk3DStV8zmI08Au7BaxRLtprGf6zpXDAD8qhACdOKjWYAZu4QNIR+1Bdr2s QbhN3uGi0XgqJF/UYbuGzgcc9SoWW/NJvTg67eIwA/TrMbK40MR/J3rqvS9K5hjT AP56WDFYZSXzwcW8jrQ77a+smQQGrbTjMtvVQukWfaDGm/A8EENIhxewS2DLJp7D pVbupNTL94EGEpLdHQ7EUkdNtehanW8aSaOjeXIk6GBcVbRcTX8qjKeisi+x5w+y LnXeSZrPmbjMH75l1vY1o/3Aap2aoazGA3/hFBABw6fJR6ucXBNvPXTlVuLbm/cj v5AAVrvjeHCbKCh85bPOHyba2N2uNF3e3MWEuLozgexI1IKdyIGCD8TKbFlpf+oz EfZHY++p974= =qMcC -----END PGP SIGNATURE-----

-- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2019-0652.html

CWE : Common Weakness Enumeration

% Id Name
67 % CWE-284 Access Control (Authorization) Issues
33 % CWE-200 Information Exposure

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 24
Application 574
Application 348
Application 1
Application 3
Application 3
Application 1
Application 14
Application 3
Application 12
Application 1
Application 210
Application 1
Application 86
Os 4
Os 2
Os 3
Os 2
Os 1
Os 2
Os 1
Os 1
Os 1
Os 1

Nessus® Vulnerability Scanner

Date Description
2019-01-02 Name : Tenable Nessus running on the remote host is affected by multiple vulnerabili...
File : nessus_tns_2018_16.nasl - Type : ACT_GATHER_INFO
2019-01-02 Name : Tenable Nessus running on the remote host is affected by multiple vulnerabili...
File : nessus_tns_2018_17.nasl - Type : ACT_GATHER_INFO
2018-12-28 Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1434.nasl - Type : ACT_GATHER_INFO
2018-12-28 Name : Node.js - JavaScript run-time environment is affected by multiple vulnerabili...
File : nodejs_2018_nov.nasl - Type : ACT_GATHER_INFO
2018-12-20 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4355.nasl - Type : ACT_GATHER_INFO
2018-12-10 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_2a86f45afc3c11e8a41400155d006b02.nasl - Type : ACT_GATHER_INFO
2018-12-01 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4348.nasl - Type : ACT_GATHER_INFO
2018-11-23 Name : The remote Slackware host is missing a security update.
File : Slackware_SSA_2018-325-01.nasl - Type : ACT_GATHER_INFO
2018-11-23 Name : The remote Debian host is missing a security update.
File : debian_DLA-1586.nasl - Type : ACT_GATHER_INFO
2018-11-13 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_6f170cf2e6b711e8a9a8b499baebfeaf.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2020-03-19 13:18:05
  • First insertion