CVE-2020-14329
Ansible Tower vulnerability analysis and mitigation

Overview

A data exposure vulnerability (CVE-2020-14329) was discovered in Ansible Tower versions before 3.7.2. The vulnerability allows users from other organizations in the system to retrieve any label from the organization and disclose organization names through the /api/v2/labels/ endpoint. The vulnerability was discovered by Maxime ESCOURBIAC from the Michelin CERT team and was addressed in August 2020 (Red Hat Advisory).

Technical details

The vulnerability exists in the /api/v2/labels/ endpoint of Ansible Tower, which was accessible to all logged-in users in the system. The endpoint's response contained labels from organizations that the user should not normally have access to, along with organization names. The vulnerability received a CVSS v3.1 Base Score of 3.3 (LOW) with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

The primary impact of this vulnerability is to data confidentiality. Authenticated users could access labels and organization names from organizations they were not authorized to view, potentially exposing sensitive organizational information (Red Hat Bugzilla).

Exploitability

The vulnerability requires an attacker to be authenticated in the system with basic user access. Once authenticated, they can access the vulnerable endpoint to retrieve unauthorized information from other organizations (NVD).

Mitigation and workarounds

The vulnerability was fixed in Ansible Tower version 3.7.2. Organizations running affected versions should upgrade to version 3.7.2 or later to address this security issue (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Ansible Tower vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-4112HIGH8.8
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesAug 25, 2022
CVE-2021-3583HIGH7.1
  • Ansible Tower logoAnsible Tower
  • python3-hwdata
NoYesSep 22, 2021
CVE-2020-14327MEDIUM5.5
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021
CVE-2020-14329LOW3.3
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021
CVE-2020-14328LOW3.3
  • Ansible Tower logoAnsible Tower
  • cpe:2.3:a:redhat:ansible_tower
NoYesMay 27, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management