CVE-2024-10033
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD (Secondary)
Description
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.
Affected (3)
Products: Redhat: Ansible Automation Platform, Ansible Developer, Ansible Inside
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.5 | |
| Version 1.2 | |
| Version 1.3 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
References (3)
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Timeline
No history available yet.