RHBA-2020:1540: Red Hat Ansible Tower 3.6.4-1 - RHEL7 Container
Added additional metrics to the Prometheus /api/v2/metrics/ endpoint for reporting remaining instance capacity Fixed Tower to allow users to subscribe to playbook output in organizations they do not have RBAC access to via Towers websocket interface (CVE-2020-10698) Fixed OAuth2 refresh tokens to properly respect custom expiration settings (CVE-2020-10709) Fixed event hostnames to be recorded for playbooks run on isolated nodes Fixed a PostgreSQL issue that caused upgrade failures in certain situations Fixed the search for Source Control credentials in the Tower user interface Fixed a performance issue to no longer delay the output of project updates for certain users Fixed the installations to no longer fail with admin passwords that contain certain special characters Fixed the start time to correctly set for approval notifications Fixed an inconsistency in gathered inventory analytics Improved memcached in OpenShift deployments to listen on a more secure domain socket (CVE-2020-10697) Updated single sign-on integration to address several upcoming GitHub API deprecations Updated the Twisted library to address CVE-2020-10108 and CVE-2020-10109 Updated translations
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHBA-2020:1540?
The severity of RHBA-2020:1540 is classified as moderate.
How do I fix RHBA-2020:1540?
To fix RHBA-2020:1540, users should apply the latest updates provided by the vendor.
What software does RHBA-2020:1540 affect?
RHBA-2020:1540 affects the Ansible Tower software.
What issues does RHBA-2020:1540 address?
RHBA-2020:1540 addresses instance capacity reporting metrics and RBAC access issues in Ansible Tower.
Is there a workaround for RHBA-2020:1540?
No specific workaround is provided for RHBA-2020:1540; updating is recommended.