Vulnerabilities > Redhat > Ansible Tower > 2.1.2

DATE CVE VULNERABILITY TITLE RISK
2019-01-03 CVE-2018-16879 Missing Encryption of Sensitive Data vulnerability in Redhat Ansible Tower
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ.
network
low complexity
redhat CWE-311
critical
9.8
2018-09-11 CVE-2016-7070 Permissions, Privileges, and Access Controls vulnerability in Redhat Ansible Tower
A privilege escalation flaw was found in the Ansible Tower.
low complexity
redhat CWE-264
5.2
2018-07-27 CVE-2017-12148 Improper Input Validation vulnerability in Redhat Ansible Tower and Cloudforms
A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories.
network
low complexity
redhat CWE-20
critical
9.0
2018-05-02 CVE-2018-1104 Code Injection vulnerability in Redhat Ansible Tower and Cloudforms
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
network
low complexity
redhat CWE-94
6.5
2018-05-02 CVE-2018-1101 Weak Password Requirements vulnerability in Redhat Ansible Tower and Cloudforms
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation.
network
low complexity
redhat CWE-521
6.5