VDB

CVE-2020-14328

CVE-2020-14328 PUBLISHED CVSS 3.299999952316284 LOW

A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal services or exposing additional internal services and more particularly retrieving full details in case of error. The highest threat from this vulnerability is to data confidentiality.

EPSS 0.24% · 15.1th percentile

Risk Scores

CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.24%
15.1th percentile

Affected Products

VendorProductVersions
redhatansible_tower0
n/aToweransible_tower 3.7.2

Timeline

  • May 27, 2021 CVE Published
  • May 28, 2021 EPSS Score
  • Jun 8, 2021 EPSS Score
  • Jun 13, 2021 EPSS Score
  • Jul 30, 2021 EPSS Score
  • Nov 30, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 30, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 1, 2022 EPSS Score
  • Aug 3, 2022 EPSS Score
  • Oct 3, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›