An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as “<”, “>”, and “&” that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ansible_automation_controller | Redhat | * | 4.3.11 (excluding) |
Ansible_automation_controller | Redhat | 4.4 (including) | 4.4 (including) |
Red Hat Ansible Automation Platform 2.3 for RHEL 8 | RedHat | automation-controller-0:4.3.11-1.el8ap | * |
Red Hat Ansible Automation Platform 2.3 for RHEL 9 | RedHat | automation-controller-0:4.3.11-1.el9ap | * |
Red Hat Ansible Automation Platform 2.4 for RHEL 8 | RedHat | automation-controller-0:4.4.1-1.el8ap | * |
Red Hat Ansible Automation Platform 2.4 for RHEL 9 | RedHat | automation-controller-0:4.4.1-1.el9ap | * |