CVE-2020-14327
Last modified
CVE-2020-14327 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ansible Tower | < 3.6.5 |
| Redhat | Ansible Tower | >= 3.7.0, < 3.7.2 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1856785Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1856785Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-14327?
How severe is CVE-2020-14327?
How do I fix CVE-2020-14327?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-14321In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of…8.8
- CVE-2020-14322In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo n…7.5
- CVE-2020-14323A null pointer dereference flaw was found in samba's Winbind…5.5
- CVE-2020-14324A high severity vulnerability was found in all active versio…9.1
- CVE-2020-14325Red Hat CloudForms before 5.11.7.0 was vulnerable to the Use…9.1
- CVE-2020-14326A vulnerability was found in RESTEasy, where RootNode incorr…7.5
- CVE-2020-14328A flaw was found in Ansible Tower in versions before 3.7.2. …3.3
- CVE-2020-14329A data exposure flaw was found in Ansible Tower in versions …3.3
- CVE-2020-1433An information disclosure vulnerability exists when Microsof…6.5
- CVE-2020-14330An Improper Output Neutralization for Logs flaw was found in…5.5
- CVE-2020-14331A flaw was found in the Linux kernel’s implementation of the…6.6
- CVE-2020-14332A flaw was found in the Ansible Engine when using module_arg…5.5
Are you affected by CVE-2020-14327?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
