CVE-2022-3205

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*

History

12 Feb 2023, 06:15

Type Values Removed Values Added
Summary CVE-2022-3205 Controller: Cross site scripting in automation controller UI Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

03 Feb 2023, 19:15

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2022-3205 -
Summary An XSS exists in automation controller UI where the project name is susceptible to XSS injection CVE-2022-3205 Controller: Cross site scripting in automation controller UI

17 Sep 2022, 00:24

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:ansible_automation_platform:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*
CWE CWE-79
First Time Redhat
Redhat ansible Automation Platform
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2120597 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2120597 - Issue Tracking, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

13 Sep 2022, 20:43

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-13 20:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-3205

Mitre link : CVE-2022-3205

CVE.ORG link : CVE-2022-3205


JSON object : View

Products Affected

redhat

  • ansible_automation_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')