216.73.217.22

CVE-2024-36110

· Published 28/05/2024 19:15 · Modified 28/05/2024 19:15

Labels: CVE-2024-36110 2024-05-28CVE-2024-36110CWE-79[email protected]

Essential information

Published
28/05/2024 19:15
Modified
28/05/2024 19:15
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L

CVSS metrics

Description

ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser. These issues have been addressed in version 0.0.21 (0.0.21.post2 on pypi). Users are advised to upgrade. There are no known workarounds for these issues.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References