The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Vulnerability of Ansible Tower: Cross Site Request Forgery via Webhooks

Synthesis of the vulnerability 

An attacker can trigger a Cross Site Request Forgery via Webhooks of Ansible Tower, in order to force the victim to perform operations.
Impacted software: Ansible Tower, Unisphere EMC.
Severity of this computer vulnerability: 2/4.
Creation date: 06/08/2020.
Références of this announce: CVE-2020-1432, DSA-2020-278, VIGILANCE-VUL-33010.

Description of the vulnerability 

An attacker can trigger a Cross Site Request Forgery via Webhooks of Ansible Tower, in order to force the victim to perform operations.
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

This threat announce impacts software or systems such as Ansible Tower, Unisphere EMC.

Our Vigil@nce team determined that the severity of this cybersecurity alert is medium.

The trust level is of type confirmed by the editor, with an origin of internet client.

An attacker with a expert ability can exploit this security alert.

Solutions for this threat 

Ansible Tower: version 3.7.2.
The version 3.7.2 is fixed:
  https://www.ansible.com/tower

Dell EMC Unisphere PowerMax: fixed versions for Third-Party Component.
Fixed versions are indicated in information sources.
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

Computer vulnerabilities tracking service 

Vigil@nce provides computers vulnerabilities patches. The Vigil@nce vulnerability database contains several thousand vulnerabilities.