CVE-2020-14329

LOW

Ansible Tower < 3.7.2 - Unauthorized Sensitive Data Exposure via Labels API Endpoint

Title source: llm
STIX 2.1

Description

A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint. This flaw allows users from other organizations in the system to retrieve any label from the organization and also disclose organization names. The highest threat from this vulnerability is to confidentiality.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1856787

Scores

CVSS v3 3.3
EPSS 0.0004
EPSS Percentile 12.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
redhat/ansible_tower < 3.7.2
Published May 27, 2021
Tracked Since Feb 18, 2026