VDB
CVE-2020-14328
CVE-2020-14328
PUBLISHED
CVSS 3.299999952316284 LOW
A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplying a URL which could lead to the server processing it connecting to internal services or exposing additional internal services and more particularly retrieving full details in case of error. The highest threat from this vulnerability is to data confidentiality.
EPSS 0.24% · 13.8th percentile
Risk Scores
CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.24%
13.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | ansible_tower | 0 |
| n/a | Tower | ansible_tower 3.7.2 |
Timeline
- May 27, 2021 CVE Published
- May 28, 2021 EPSS Score
- Jun 8, 2021 EPSS Score
- Jun 13, 2021 EPSS Score
- Sep 30, 2021 EPSS Score
- Dec 1, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 31, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 3, 2022 EPSS Score
- Aug 5, 2022 EPSS Score
- Oct 6, 2022 EPSS Score