For information on upgrading Ansible Tower, reference the Ansible Tower
Upgrade and Migration Guide:
https://legacy-controller-docs.ansible.com/ansible-tower/
index.html
* Fixed an XSS vulnerability (CVE-2020-25626)
* Fixed the Red Hat sosreport tool to no longer include the Ansible Tower
SECRET_KEY value
* Fixed the Ansible Tower installer so that it is now compatible with the
latest supported Red Hat OpenShift Container Platforms 3.x and 4.x
https://access.redhat.com/security/cve/CVE-2020-14365 https://access.redhat.com/security/cve/CVE-2020-25626 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container
1878635 - CVE-2020-25626 django-rest-framework: XSS Vulnerability in API viewer
Get the latest Linux and open source security news straight to your inbox.