CVE-2023-3971
published 2023-10-04CVE-2023-3971: An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.67%
47.9th percentile
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ansible_automation_controller | < 4.3.11 | 4.3.11 |
| redhat | ansible_automation_controller | — | — |
| redhat | ansible_automation_platform | — | — |
| redhat | ansible_automation_platform | — | — |
| redhat | ansible_developer | — | — |
| redhat | ansible_inside | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5xq-xr8f-3wj4: An HTML injection flaw was found in Controller in the user interface settings
ghsa_unreviewed·2023-10-04
CVE-2023-3971 [MEDIUM] CWE-79 GHSA-p5xq-xr8f-3wj4: An HTML injection flaw was found in Controller in the user interface settings
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
Red Hat
Controller: Html injection in custom login info
vendor_redhat·2023-07-27·CVSS 7.3
CVE-2023-3971 [HIGH] CWE-80 Controller: Html injection in custom login info
Controller: Html injection in custom login info
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:4340https://access.redhat.com/errata/RHSA-2023:4590https://access.redhat.com/security/cve/CVE-2023-3971https://bugzilla.redhat.com/show_bug.cgi?id=2226965https://access.redhat.com/errata/RHSA-2023:4340https://access.redhat.com/errata/RHSA-2023:4590https://access.redhat.com/security/cve/CVE-2023-3971https://bugzilla.redhat.com/show_bug.cgi?id=2226965
2023-10-04
Published