VulnerabilityModified
CVE-2023-3971
An HTML injection flaw was found in Controller in the user interface settings.
MEDIUM 5.4EPSS 0.81%
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-80, CWE-79
- Affected
- redhat/ansible automation controller · redhat/ansible automation platform · redhat/ansible developer · redhat/ansible inside
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2023:4340Vendor Advisory
- https://access.redhat.com/errata/RHSA-2023:4590Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3971Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2226965Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2023:4340Vendor Advisory
- https://access.redhat.com/errata/RHSA-2023:4590Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-3971Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2226965Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.