cbcvebase.
CVE-2023-3971
published 2023-10-04

CVE-2023-3971: An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

Affected

6 ranges
VendorProductVersion rangeFixed in
redhatansible_automation_controller< 4.3.114.3.11
redhatansible_automation_controller
redhatansible_automation_platform
redhatansible_automation_platform
redhatansible_developer
redhatansible_inside