CVE-2018-16879 - CVE House
Back to Database
Status published High CVE-2018-16879

Ansible Tower before version 3.3.3 does not set a secure...

Vulnerability Description

Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16879

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Tower
Vulnerable Versions:
3.3.3

Timeline

Official Publish: January 3rd, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)