CVE-2024-10033: Red Hat Ansible Automation Platform

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.

Affected products

  • Red Hat Ansible Automation Platform: version 2.5 only
  • Red Hat Ansible Developer: version 1.2 only
  • Red Hat Ansible Inside: version 1.3 only

Published 2024-10-16. Last modified 2026-06-17.