RHBA-2020:1540: Red Hat Ansible Tower 3.6.4-1 - RHEL7 Container

Published Apr 22, 2020
·
Updated

Added additional metrics to the Prometheus /api/v2/metrics/ endpoint for reporting remaining instance capacity Fixed Tower to allow users to subscribe to playbook output in organizations they do not have RBAC access to via Towers websocket interface (CVE-2020-10698) Fixed OAuth2 refresh tokens to properly respect custom expiration settings (CVE-2020-10709) Fixed event hostnames to be recorded for playbooks run on isolated nodes Fixed a PostgreSQL issue that caused upgrade failures in certain situations Fixed the search for Source Control credentials in the Tower user interface Fixed a performance issue to no longer delay the output of project updates for certain users Fixed the installations to no longer fail with admin passwords that contain certain special characters Fixed the start time to correctly set for approval notifications Fixed an inconsistency in gathered inventory analytics Improved memcached in OpenShift deployments to listen on a more secure domain socket (CVE-2020-10697) Updated single sign-on integration to address several upcoming GitHub API deprecations Updated the Twisted library to address CVE-2020-10108 and CVE-2020-10109 Updated translations

Affected Software

1 affected component
Red Hat Ansible Tower

Remediation

Event History

Apr 22, 2020
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHBA-2020:1540?

The severity of RHBA-2020:1540 is classified as moderate.

2

How do I fix RHBA-2020:1540?

To fix RHBA-2020:1540, users should apply the latest updates provided by the vendor.

3

What software does RHBA-2020:1540 affect?

RHBA-2020:1540 affects the Ansible Tower software.

4

What issues does RHBA-2020:1540 address?

RHBA-2020:1540 addresses instance capacity reporting metrics and RBAC access issues in Ansible Tower.

5

Is there a workaround for RHBA-2020:1540?

No specific workaround is provided for RHBA-2020:1540; updating is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203