Bug 1782625 (CVE-2019-19341) - CVE-2019-19341 Tower: intermediate files during Tower backup are world-readable
Summary: CVE-2019-19341 Tower: intermediate files during Tower backup are world-readable
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-19341
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1782631 1782699
Blocks: 1782618
TreeView+ depends on / blocked
 
Reported: 2019-12-12 01:01 UTC by Borja Tarraso
Modified: 2019-12-20 17:55 UTC (History)
14 users (show)

Fixed In Version: ansible_tower 3.6.2
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Ansible Tower 3.6.1 and 3.5.3 where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest threat with this vulnerability.
Clone Of:
Environment:
Last Closed: 2019-12-16 20:09:29 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:4242 None None None 2019-12-16 18:34:23 UTC
Red Hat Product Errata RHSA-2019:4243 None None None 2019-12-16 18:36:37 UTC

Description Borja Tarraso 2019-12-12 01:01:26 UTC
While a Tower backup is running, files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup, any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower.

Comment 1 Borja Tarraso 2019-12-12 01:01:29 UTC
Acknowledgments:

Name: Graham Mainwaring (Red Hat)

Comment 6 errata-xmlrpc 2019-12-16 18:34:20 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Tower 3.5 for RHEL 7

Via RHSA-2019:4242 https://access.redhat.com/errata/RHSA-2019:4242

Comment 7 errata-xmlrpc 2019-12-16 18:36:35 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Tower 3.6 for RHEL 7

Via RHSA-2019:4243 https://access.redhat.com/errata/RHSA-2019:4243

Comment 8 Product Security DevOps Team 2019-12-16 20:09:29 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-19341

Comment 9 Yadnyawalk Tale 2019-12-17 19:20:06 UTC
Statement:

Red Hat CloudForms 4.7 (5.10) release is not affected, because we do not run Ansible Tower backups from CloudForms.


Note You need to log in before you can comment on or make changes to this bug.