Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.
CVSS Information
N/A
Vulnerability Type
敏感数据加密缺失
Vulnerability Title
Ansible Tower 信息泄露漏洞
Vulnerability Description
Ansible是美国Ansible公司的一款计算机系统配置管理器,它可用于发布、管理和编排计算机系统。Ansible Tower(又名Ansible UI)是其中的一个提供了用户界面(UI)、仪表板和REST API的任务控制应用程序。 Ansible Tower 3.3.3之前版本中存在信息泄露漏洞,该漏洞源于程序没有正确的为AMPQ连接设置安全通道。远程攻击者可利用该漏洞泄露敏感信息(例如:密码)并造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A