CVE-2017-7528: Red Hat Ansible Tower

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).

Affected products

  • Red Hat Ansible Tower: affected versions not specified
  • Red Hat Cloudforms Management Engine: version 5.0 only

Published 2018-08-22. Last modified 2026-06-17.