CVE-2022-3205
published 2022-09-13CVE-2022-3205: Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.44%
35.3th percentile
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ansible_automation_platform | — | — |
| redhat | ansible_automation_platform | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-24jx-rfj6-x4mp: An XSS exists in automation controller UI where the project name is susceptible to XSS injection
ghsa_unreviewed·2022-09-14
CVE-2022-3205 [MEDIUM] CWE-79 GHSA-24jx-rfj6-x4mp: An XSS exists in automation controller UI where the project name is susceptible to XSS injection
An XSS exists in automation controller UI where the project name is susceptible to XSS injection
Red Hat
Controller: Cross site scripting in automation controller UI
vendor_redhat·2022-08-23·CVSS 4.6
CVE-2022-3205 [MEDIUM] CWE-79 Controller: Cross site scripting in automation controller UI
Controller: Cross site scripting in automation controller UI
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
Package: ansible-tower (Red Hat Ansible Automation Platform 1.2) - Will not fix
Package: automation-controller (Red Hat Ansible Automation Platform 2) - Affected
No detection rules found.
No public exploits indexed.
2022-09-13
Published