Home / mailings [RHSA-2019:4243-01] Important: Red Hat Ansible Tower 3.6.2-1 - RHEL7 Container
Posted on 16 December 2019
RedHat===================================================================== Red Hat Security Advisory
Synopsis: Important: Red Hat Ansible Tower 3.6.2-1 - RHEL7 Container
Advisory ID: RHSA-2019:4243-01
Product: Red Hat Ansible Tower
Advisory URL: https://access.redhat.com/errata/RHSA-2019:4243
Issue date: 2019-12-16
CVE Names: CVE-2019-19340 CVE-2019-19341 CVE-2019-19342
=====================================================================
1. Summary:
Red Hat Ansible Tower 3.6.2-1 - RHEL7 Container
2. Description:
* Added a command to generate a new SECRET_KEY and rekey the database
* Removed the guest user from the optionally-configured RabbitMQ admin
interface (CVE-2019-19340)
* Fixed slow queries for /api/v2/instances and /api/v2/instance_groups when
smart inventories are used
* Fixed assorted issues with preserving permissions in the Ansible Tower
backup playbook (CVE-2019-19341)
* Fixed a partial password disclosure when special characters existed in
the RabbitMQ password (CVE-2019-19342)
* Fixed hang in error handling for source control checkouts
* Fixed an error on subsequent job runs that override the branch of a
project on an instance that did not have a prior project checkout
* Fixed an issue where supervisord would not shut down correctly
* Fixed an issue where jobs launched in isolated or container groups would
incorrectly timeout
* Fixed link to instance groups documentation in the user interface
* Fixed retrieval of Red Hat subscription data when running in OpenShift
* Fixed editing of inventory on Workflow templates
* Fixed multiple issues with OAuth2 token cleanup system jobs
* Fixed custom email notifications for workflow approve and deny
* Updated SAML implementation to automatically log if authorization exists
* Updated AngularJS to 1.7.9 for CVE-2019-10768
* Updated installer to not install PostgreSQL server on all nodes
* Updated bundled installer to contain both Red Hat Enterprise Linux 7 and
8 builds
3. Solution:
For information on upgrading Ansible Tower, reference the Ansible Tower
Upgrade and Migration Guide:
https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/
index.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1782623 - CVE-2019-19342 Tower: special characters in RabbitMQ passwords causes web socket 500 error
1782624 - CVE-2019-19340 Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
1782625 - CVE-2019-19341 Tower: intermediate files during Tower backup are world-readable
5. References:
https://access.redhat.com/security/cve/CVE-2019-19340
https://access.redhat.com/security/cve/CVE-2019-19341
https://access.redhat.com/security/cve/CVE-2019-19342
https://access.redhat.com/security/updates/classification/#important
6. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc.