Описание
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Certificate System 10 | pki-core | Affected | ||
| Red Hat Certificate System 9.4 EUS | idm-console-framework | Fixed | RHSA-2021:0948 | 23.03.2021 |
| Red Hat Certificate System 9.4 EUS | pki-console | Fixed | RHSA-2021:0948 | 23.03.2021 |
| Red Hat Certificate System 9.4 EUS | pki-core | Fixed | RHSA-2021:0948 | 23.03.2021 |
| Red Hat Certificate System 9.4 EUS | redhat-pki-theme | Fixed | RHSA-2021:0948 | 23.03.2021 |
| Red Hat Certificate System 9.7 | pki-core | Fixed | RHSA-2021:0947 | 22.03.2021 |
| Red Hat Certificate System 9.7 | redhat-pki-theme | Fixed | RHSA-2021:0947 | 22.03.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.6 Medium
CVSS3
Связанные уязвимости
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
It was found that the Token Processing Service (TPS) did not properly ...
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
EPSS
4.6 Medium
CVSS3