Description
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13482 | When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:19:18.595Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3869
No data.
Status : Modified
Published: 2019-03-28T14:29:00.307
Modified: 2024-11-21T04:42:45.570
Link: CVE-2019-3869
OpenCVE Enrichment
No data.
EUVD