A Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container security update has been released.
RHSA-2020:4137-01: Moderate: security update - Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: security update - Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container
Advisory ID: RHSA-2020:4137-01
Product: Red Hat Ansible Tower
Advisory URL: https://access.redhat.com/errata/RHSA-2020:4137
Issue date: 2020-09-30
CVE Names: CVE-2020-14365 CVE-2020-25626
=====================================================================
1. Summary:
Red Hat Ansible Tower 3.6.6-1 - RHEL7 Container
2. Description:
* Fixed an XSS vulnerability (CVE-2020-25626)
* Fixed the Red Hat sosreport tool to no longer include the Ansible Tower
SECRET_KEY value
* Fixed the Ansible Tower installer so that it is now compatible with the
latest supported Red Hat OpenShift Container Platforms 3.x and 4.x
3. Solution:
For information on upgrading Ansible Tower, reference the Ansible Tower
Upgrade and Migration Guide:
https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/
index.html
4. Bugs fixed ( https://bugzilla.redhat.com/):
1878635 - CVE-2020-25626 django-rest-framework: XSS Vulnerability in API viewer
5. References:
https://access.redhat.com/security/cve/CVE-2020-14365
https://access.redhat.com/security/cve/CVE-2020-25626
https://access.redhat.com/security/updates/classification/#moderate
6. Contact:
The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2020 Red Hat, Inc.