Impact
The vulnerability allows an authenticated user with content upload permissions to upload a crafted HTML or SVG file that is served with its original content type and without a Content-Disposition header. When an end‑user visits the file URL, the embedded JavaScript is executed in the browser context of the host web application, creating a stored cross‑site scripting condition that can compromise the confidentiality, integrity, and availability of user sessions. This flaw is classified as a stored XSS issue (CWE‑79).
Affected Systems
Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Update Infrastructure 5, and the associated Red Hat RHUI 4 and RHUI 5 products are impacted by the vulnerability.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is not currently available, and the vulnerability is not listed in the CISA KEV catalog. Exploitability requires that an attacker have valid upload credentials; once the malicious content is persisted, any user who accesses the file URL is exposed to script execution. The attack vector is thus an authenticated upload scenario, which is inferred from the description of the flaw and the controls that were bypassed. The overall risk is moderate to high in environments where broad upload permissions are granted, especially in production deployments of the affected Red Hat products.
OpenCVE Enrichment