Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10146

Опубликовано: 03 фев. 2020
Источник: redhat
CVSS3: 4.7

Описание

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.

A Reflected Cross Site Scripting flaw was found in the pki-ca module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.

Отчет

This flaw is considered Low, because it requires the attacker to first request or predict a valid nonce. Without a valid nonce, no arbitrary HTML will be sent back to the victim's browser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pki-coreNot affected
Red Hat Enterprise Linux 7pki-coreFixedRHSA-2021:085116.03.2021
Red Hat Enterprise Linux 7.6 Extended Update Supportpki-coreFixedRHSA-2021:081915.03.2021
Red Hat Enterprise Linux 7.7 Extended Update Supportpki-coreFixedRHSA-2021:097523.03.2021
Red Hat Enterprise Linux 8pki-coreFixedRHSA-2020:484704.11.2020
Red Hat Enterprise Linux 8pki-depsFixedRHSA-2020:484704.11.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1710171pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 5 лет назад

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.

CVSS3: 4.7
nvd
больше 5 лет назад

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.

CVSS3: 4.7
debian
больше 5 лет назад

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x ...

CVSS3: 4.7
github
около 3 лет назад

A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.

oracle-oval
больше 4 лет назад

ELSA-2021-0851: pki-core security and bug fix update (IMPORTANT)

4.7 Medium

CVSS3