Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).
2018-08-22T16:29:03.040
2024-11-21T03:32:05.187
Modified
CVSSv3.0: 5.2 (MEDIUM)
AV:A/AC:L/Au:N/C:N/I:P/A:N
6.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | ansible_tower | - | Yes |
Application | redhat | cloudforms_management_engine | 5.0 | Yes |