VYPR
Medium severity5.3NVD Advisory· Published Dec 19, 2019· Updated Jun 17, 2026

CVE-2019-19342

CVE-2019-19342

Description

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial password disclose will occur in plaintext. An attacker could easily guess some predictable passwords or brute force the password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:redhat:ansible_tower:*:*:*:*:*:*:*:*
    Range: >=3.5.0,<3.5.4
  • Ansible/Towerllm-fuzzy
    Range: <3.6.2, <3.5.4
  • Red Hat/Towerv5
    Range: all ansible_tower versions 3.6.x before 3.6.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.