An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. A malicious user could use it to perform actions to impact users by using the "?next=" in a URL and hence redirecting, injecting malicious script, stealing session and data.
Moderate: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Important: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.5 Product Release Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
Moderate: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update