VDB

CVE-2020-14327

CVE-2020-14327 PUBLISHED CVSS 5.5 MEDIUM

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.

EPSS 0.25% · 16.2th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.25%
16.2th percentile

Affected Products

VendorProductVersions
redhatansible_tower0, 3.7.0
n/aToweransible_tower 3.6.5, ansible_tower 3.7.2

Timeline

  • May 27, 2021 CVE Published
  • May 28, 2021 EPSS Score
  • Jun 8, 2021 EPSS Score
  • Jun 13, 2021 EPSS Score
  • Jul 30, 2021 EPSS Score
  • Nov 30, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 30, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 1, 2022 EPSS Score
  • Aug 3, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›