CVE Database
/

CVE-2020-14327

Back to search

CVE-2020-14327

Published: May 27, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is abused by supplying a URL that could lead to the server processing it. This flaw leads to the connection to internal services or the exposure of additional internal services by abusing the test feature of lookup credentials to forge HTTP/HTTPS requests from the server and retrieving the results of the response.

VendorProductVersions

n/a

Tower

affected
ansible_tower 3.6.5, ansible_tower 3.7.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now