Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10180

Опубликовано: 03 фев. 2020
Источник: redhat
CVSS3: 2.4

Описание

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

It was found that the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10pki-coreAffected
Red Hat Certificate System 9.4 EUSidm-console-frameworkFixedRHSA-2021:094823.03.2021
Red Hat Certificate System 9.4 EUSpki-consoleFixedRHSA-2021:094823.03.2021
Red Hat Certificate System 9.4 EUSpki-coreFixedRHSA-2021:094823.03.2021
Red Hat Certificate System 9.4 EUSredhat-pki-themeFixedRHSA-2021:094823.03.2021
Red Hat Certificate System 9.7pki-coreFixedRHSA-2021:094722.03.2021
Red Hat Certificate System 9.7redhat-pki-themeFixedRHSA-2021:094722.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1721137pki-core: unsanitized token parameters in TPS resulting in stored XSS

2.4 Low

CVSS3

Связанные уязвимости

CVSS3: 2.4
ubuntu
почти 6 лет назад

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

CVSS3: 2.4
nvd
почти 6 лет назад

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

CVSS3: 2.4
debian
почти 6 лет назад

A vulnerability was found in all pki-core 10.x.x version, where the To ...

CVSS3: 4.8
github
больше 3 лет назад

A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

2.4 Low

CVSS3