Vulnerabilities > Redhat > Ansible Tower > 3.2.7

DATE CVE VULNERABILITY TITLE RISK
2019-03-28 CVE-2019-3869 Information Exposure vulnerability in Redhat Ansible Tower
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables.
network
low complexity
redhat CWE-200
4.0
2019-01-03 CVE-2018-16879 Missing Encryption of Sensitive Data vulnerability in Redhat Ansible Tower
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ.
network
low complexity
redhat CWE-311
critical
9.8