Using '-e rabbitmq_enable_manager=true' in the installer exposes the RabbitMQ management interface publicly with a guessable admin user.
Acknowledgments: Name: Ryan Petrello (Red Hat)
This issue has been addressed in the following products: Red Hat Ansible Tower 3.5 for RHEL 7 Via RHSA-2019:4242 https://access.redhat.com/errata/RHSA-2019:4242
This issue has been addressed in the following products: Red Hat Ansible Tower 3.6 for RHEL 7 Via RHSA-2019:4243 https://access.redhat.com/errata/RHSA-2019:4243
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-19340
Mitigation: The issue could be mitigated by limiting the access of the interface to internal trusted networks, limiting the ports open and set the firewall with more restrictive rules. Some of these instructions are already suggested in the Ansible Tower documentation as part of the Ansible Tower Administration Guide. Issue could be also mitigated by deleting the guest default user by running the command "rabbitmqctl delete_user guest".