VYPR
High severity7.3NVD Advisory· Published Oct 4, 2023· Updated Jun 17, 2026

CVE-2023-3971

CVE-2023-3971

Description

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:/a:redhat:ansible_automation_platform_developer:2.3::el9+ 3 more
    • cpe:/a:redhat:ansible_automation_platform_developer:2.3::el9range: 0:4.3.11-1.el9ap
    • cpe:/a:redhat:ansible_automation_platform:2.4::el8range: 0:4.4.1-1.el9ap
    • cpe:2.3:a:redhat:ansible_automation_platform:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:ansible_automation_controller:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:ansible_automation_controller:*:*:*:*:*:*:*:*range: <4.3.11
    • cpe:2.3:a:redhat:ansible_automation_controller:4.4:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:ansible_developer:1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:ansible_inside:1.1:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.