CVE-2022-3205

MEDIUM

Red Hat Ansible Automation Platform <2.0 - XSS

Title source: llm
STIX 2.1

Description

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

References (2)

Core 2
Core References
Vendor Advisory vdb-entry x_redhatref
https://access.redhat.com/security/cve/CVE-2022-3205
Issue Tracking, Vendor Advisory issue-tracking x_redhatref
https://bugzilla.redhat.com/show_bug.cgi?id=2120597

Scores

CVSS v3 4.6
EPSS 0.0051
EPSS Percentile 66.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
redhat/ansible_automation_platform 1.2
redhat/ansible_automation_platform 2.0
Published Sep 13, 2022
Tracked Since Feb 18, 2026