CVE-2024-10033: Aap-gateway: xss on aap-gateway
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. A malicious user could use it to perform actions to impact users by using the "?next=" in a URL and hence redirecting, injecting malicious script, stealing session and data.
Other sources
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10033?
CVE-2024-10033 is classified as a Cross-site Scripting (XSS) vulnerability, which can lead to significant security risks for affected applications.
How do I fix CVE-2024-10033?
To fix CVE-2024-10033, it is recommended to update the affected software components to the latest patched versions provided by Red Hat.
What software is affected by CVE-2024-10033?
CVE-2024-10033 affects Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Developer 1.2, and Red Hat Ansible Inside 1.3.
What type of attack can be executed using CVE-2024-10033?
Exploitation of CVE-2024-10033 allows a malicious user to inject scripts into web pages viewed by other users, leading to potential data theft or session hijacking.
Is Red Hat Enterprise Linux affected by CVE-2024-10033?
CVE-2024-10033 does not affect Red Hat Enterprise Linux versions 8.0 and 9.0.