A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2019-12-19T20:16:46

Updated: 2024-08-05T02:16:46.967Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2019-19340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-12-19T21:15:13.887

Modified: 2023-02-01T18:02:22.727

Link: CVE-2019-19340

cve-icon Redhat

Severity : Important

Publid Date: 2019-12-14T00:00:00Z

Links: CVE-2019-19340 - Bugzilla