Lucene search

K
redhatRedHatRHSA-2018:3505
HistoryNov 06, 2018 - 3:39 p.m.

(RHSA-2018:3505) Critical: Red Hat Ansible Tower 3.3.1-2 Release - Container Image

2018-11-0615:39:03
access.redhat.com
619

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.313

Percentile

97.0%

Red Hat Ansible Tower 3.3.1 is now available and contains the following bug fixes:

  • Fixed event callback error when in-line vaulted variables are used with include_vars
  • Fixed HSTS and X-Frame-Options to properly be set in nginx configuration
  • Fixed isolated node setup to no longer fail when ansible_host is used
  • Fixed selection of custom virtual environments in job template creation
  • Fixed websockets for job details to properly work
  • Fixed the /api/v2/authtoken compatibility shim
  • Fixed page size selection on the jobs screen
  • Fixed instances in an instance group to properly be disabled in the user interface
  • Fixed the job template selection in workflow creation to properly render
  • Fixed member_attr to properly set on some LDAP configurations during upgrade, preventing login
  • Fixed PosixUIDGroupType LDAP configurations
  • Improved the RAM requirement in the installer preflight check
  • Updated Tower to properly report an error when relaunch was used on a set of failed hosts that is too large
  • Updated sosreport configuration to gather more python environment, nginx, and supervisor configuration
  • Fixed display of extra_vars for scheduled jobs

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.313

Percentile

97.0%