PT-2020-9050 · Pki-Core+3 · Pki-Core+3

Pedro Sampaio

·

Published

2020-03-18

·

Updated

2023-02-12

·

CVE-2019-10146

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pki-core versions 10.x.x
Description A Reflected Cross Site Scripting flaw was found in the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.
Recommendations For pki-core versions 10.x.x, ensure the CA Agent Service properly sanitizes the certificate request page to prevent the injection of specially crafted values. As a temporary workaround, consider restricting access to the certificate request page until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CESA-2020_4847
CESA-2021_0851
CVE-2019-10146
RHSA-2020:4847
RHSA-2020_4847
RHSA-2021:0819
RHSA-2021:0851
RHSA-2021:0975
RHSA-2021_0851
RLSA-2020:4847

Affected Products

Centos
Red Hat
Rocky Linux
Pki-Core