VDB

CVE-2020-14337

CVE-2020-14337 PUBLISHED CVSS 5.800000190734863 MEDIUM

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.

EPSS 1.49% · 72.1th percentile

Risk Scores

CVSS 3.1
5.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS Score
1.49%
72.1th percentile

Affected Products

VendorProductVersions
redhatansible_tower3.0.0
n/aAnsible TowerAnsible Tower 3.7.1 as well as previous versions are affected.

Timeline

  • Jul 31, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • May 24, 2022 CVE Updated
  • Jul 3, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›