CVE-2020-14337: Red Hat Ansible Tower

Medium severity, CVSS 5.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.

Affected products

  • Red Hat Ansible Tower: version 3.0.0 only

Published 2020-07-31. Last modified 2026-06-17.