Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2022-3205 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2120597 | vendor advisory issue tracking |