
Cloud Vulnerability DB
A community-led vulnerabilities database
A Server-side request forgery (SSRF) vulnerability was identified in Ansible Tower versions before 3.6.5 and before 3.7.2. The vulnerability allows attackers to abuse functionality on the Tower server by supplying malicious URLs that could lead to unauthorized server processing (NVD, Red Hat CVE).
The vulnerability exists in the test feature of lookup credentials, where attackers can forge HTTP/HTTPS requests from the server and retrieve response results. By default, the connector makes a POST request to /authn/ to authenticate and check credential configuration. Using a malicious Apache server with mod_rewrite, attackers can generate arbitrary GET/POST requests (307 redirection) on the internal network. Additionally, the POST request body can be manipulated through the api_key parameter, and the proxy defined in the application settings was not considered (Bugzilla). The vulnerability has been assigned a CVSS v3.1 score of 5.5 (MEDIUM) (NVD).
The primary impact of this vulnerability is to data confidentiality. The flaw leads to potential connection to internal services or exposure of additional internal services by abusing the test feature of lookup credentials (CVE).
The vulnerability can be exploited by any logged-in user who can abuse the test feature to forge HTTP/HTTPS requests from the AWX server and directly receive the response. The exploitation involves using a malicious Apache server configuration to generate unauthorized requests within the internal network (Bugzilla).
The vulnerability has been addressed in Ansible Tower versions 3.6.5 and 3.7.2. Users are advised to upgrade to these or later versions. Red Hat has released security updates through RHSA-2020:3328 and RHSA-2020:3329 to address this vulnerability (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."