Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

RedHat: RHSA-2020-4137-01 Moderate: Ansible Tower XSS Issue

red hat
Calendar Grey September 30, 2020
Dist Redhat Esm H88
The latest update for Red Hat Ansible Tower version 3.6.6-1 fixes vulnerabilities related to XSS and enhances overall compatibility.
Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container 2

Solution

For information on upgrading Ansible Tower, reference the Ansible Tower Upgrade and Migration Guide: https://legacy-controller-docs.ansible.com/ansible-tower/ index.html

Summary

* Fixed an XSS vulnerability (CVE-2020-25626) * Fixed the Red Hat sosreport tool to no longer include the Ansible Tower SECRET_KEY value * Fixed the Ansible Tower installer so that it is now compatible with the latest supported Red Hat OpenShift Container Platforms 3.x and 4.x

References

https://access.redhat.com/security/cve/CVE-2020-14365 https://access.redhat.com/security/cve/CVE-2020-25626 https://access.redhat.com/security/updates/classification/#moderate

Package List


Advisory ID: RHSA-2020:4137-01
Product: Red Hat Ansible Tower
Issue date: 2020-09-30

Topic

Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container

Relevant Releases Architectures

Bugs Fixed

1878635 - CVE-2020-25626 django-rest-framework: XSS Vulnerability in API viewer

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here