CVE-2019-19342 is a medium-severity vulnerability affecting Ansible Tower versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4. This flaw occurs when a password containing a '#' character is used in a /websocket request, leading to a RabbitMQ socket error and an HTTP 500 response. The vulnerability results in partial plaintext disclosure of the password, enabling attackers to potentially guess or brute-force credentials. The attack vector is network-based with low attack complexity, requiring no user interaction. While the impact is limited to partial password disclosure (Confidentiality Low), it could compromise authentication. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.5.4CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* | ||
>= 3.6.0, < 3.6.2CPE matchmatch criteria | cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.